Loading…
Attending this event?
Thursday, June 27 • 2:15pm - 3:00pm
Hacker Traction through GitHub Actions - Is Your (Open Source) Project Safe?

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

GitHub Actions are a part of every open source project either directly or indirectly. This is an often overlooked attack surface extension in the scope of Application Security which is beginning to attract those eager to compromise both open-source and commercial projects via off-the-radar upstream dependencies. 


To achieve control or write permissions on a repository, attackers draw from a range of established techniques like repo jacking, GitHub Actions command injection and more.


We know that dependencies have dependencies. It also happens that Actions have Actions which have Actions. The nest of dependencies within our CI/CD is complex and certainly mostly unobserved.  


In this talk, we'll introduce some of the common misconfigurations with GitHub pipelines and from there explore the breadth and depth of GitHub Actions dependencies alongside research into the top 1000 GitHub projects showing the potential upstream attack paths to major projects. 


Speakers
avatar for Stephen Giguere

Stephen Giguere

Developer Advocate, Palo Alto Networks
Steve started his cybersecurity life by being kicked out of his high school computing class for privilege escalation on the school Linux system and changing all passwords to "peaches" (his dog's name).  But that was a long time ago.  Since then he has experienced a wide breadth... Read More →


Thursday June 27, 2024 2:15pm - 3:00pm WEST
Feedback form isn't open yet.

Attendees (1)