Hacking your infra from the outside by exploiting npm Dependency Confusion attacks

Hacking your infra from the outside by exploiting npm Dependency Confusion attacks

説明:

What happens when you incorrectly manage your private packages registry, your developers misconfigure their local npm proxy, and malicious actors are free to abuse an open-source ecosystem? It's called Dependency Confusion and it's an attack that enabled security researchers to infiltrate big-name corps. You don't want to be the next victim on the headlines, right? Let me take you on a step-by-step deep dive into how this attack manifests and how you can defend against it.

講演者:

Liran Tal

Director of Developer Relations, Snyk

Snyk (スニーク) は、デベロッパーセキュリティプラットフォームです。Snyk は、コードやオープンソースとその依存関係、コンテナや IaC (Infrastructure as a Code) における脆弱性を見つけるだけでなく、優先順位をつけて修正するためのツールです。世界最高峰の脆弱性データベースを基盤に、Snyk の脆弱性に関する専門家としての知見が提供されます。

無料で始める資料請求

© 2024 Snyk Limited
Registered in England and Wales

logo-devseccon