54 karma · joined December 9, 2019
Classifying a command can be a bit of a misnomer because it has two inherent problems:
1. You need a classifier. That means the security boundary becomes “can I trick or bypass the classifier?” Whether it is a smaller model or a pile of regexes, it will eventually have edge cases.
2. The token economics do not work, and it also needs to be fast. I do not want an eval evaluating another eval for every command.
So the approach I took is closer to how we normally build security systems: secure defaults and deterministic boundaries.
For example, to protect secrets, AgentJail can block access to paths like `~/.ssh`, `~/.aws/credentials`, `.env`, etc. at the OS level.
The OS is the deterministic boundary here. The ring-0 enforcement layer.
The more interesting problem is network access. You may genuinely want the agent to debug a production Kubernetes cluster, inspect an AWS resource, or query a production database. A blanket network deny would make the agent useless.
For that, I am taking a protocol-aware DSL approach. Something like:
``` deny if { request.host == "api.github.com" request.method == "POST" startswith(request.path, "/repos/") endswith(request.path, "/git/refs") }
ask if { request.host == "kubernetes.default.svc" request.method == "DELETE" }
allow if { request.host == "api.github.com" request.method == "GET" } ```
So instead of trying to classify whether a command is “dangerous,” the policy describes exactly which resources and operations are allowed, denied, or require approval.
The agent can still be probabilistic. The enforcement boundary should not be.
Does that answer to your question?
Protocol aware network proxy coming soon Then you can match a DSL and block particular network requests.
This ensures you no longer fear --dangerously-skip-permissions and stop babysitting agents
What else would you want to see in this project? Please star the repo, if you like the idea :)
Protocol aware network proxy coming soon Then you can match a DSL and block particular network requests.
This ensures you no longer fear --dangerously-skip-permissions and stop babysitting agents
What else would you want to see in this project? Please star the repo, if you like the idea :)
· OS native sandbox (<4ms start-time) · Policies for AWS, local files, k8s, DBs etc. · Rego backed policies w/ OPA (CNCF Graduated project) · Fastest policy evaluator (<3ms)
Please star the repo if you like the work.
shameless self-plug. I've been dogfooding it for the last 3 weeks now.
Thanks for sharing this.
Three names, actually: 1. Hedonic Adaptation : Brain's inbuilt boredom machine 2. Rosy Retrospection : Your Memory is a Highlight Reel 3. Declinism : The "Kids These Days" Bias
Note: No personal data was ever shared or harvested. This was responsibly disclosed to the authorities through proper channels and only after the disclosure timeline (120 days) was it published in the online media.
RCE in git By cloning a repo - 'git clone --recursive <git_repo>' , your machine could be compromised. Works on MacOS and Windows Fix - Upgrade git Technical walkthrough and how you can reproduce it
``` https://foundationalsec.com/
Unable to communicate securely with peer: requested domain name does not match the server’s certificate.
HTTP Strict Transport Security: false
HTTP Public Key Pinning: false
```
Screenshot here -> https://postimg.cc/gallery/cdQsCzd
If you’re tasked with the responsibility for getting your organisation's app or website's pentest done, this blog would definitely help you navigate the waters easily.
1⃣ Deep Recursion Attack - Attack & Defend (max depth)
2⃣ GraphQL Introspection
Thanks to Dolev Farhi for the awesome DVGA
#bugbounty #cybersecurity
Area of expertise : App Security ( Web & Mobile ), Infrastructure Security etc.
Technologies: Python, Go, Terraform, AWS, GCP, Vault, CIS Benchmarks, Docker, kubernetes ( k8s ), gitlab CI/CD & github actions, Jenkins, ELK
Résumé/CV: https://aseemshrey.in/resume.html
Email: hi@aseemshrey.in
Blog : https://aseemshrey.in/
YouTube : HackingSimplified : https://www.youtube.com/channel/UCARsgS1stRbRgh99E63Q3ng
I build scalable security solutions as well, for my current employer as well as in a previous startup where I built a lot of systems from scratch.
I teach on my youtube channel hackingsimplified , about cybersecurity stuff.
Available for consulting as well.
Remote: Yes
Willing to relocate: Yes
Technologies: Python, Go, Terraform, AWS, GCP, Vault, CIS Benchmarks, Docker, kubernetes ( k8s ), gitlab CI/CD & github actions, Jenkins, ELK
Résumé/CV: https://aseemshrey.in/resume.html
Email: hi@aseemshrey.in
Blog : https://aseemshrey.in/
YouTube : HackingSimplified : https://www.youtube.com/channel/UCARsgS1stRbRgh99E63Q3ng
My area of expertise App Security ( Web & Mobile ), Infrastructure Security etc.
I build scalable security solutions as well, for my current employer as well as in a previous startup where I built a lot of systems from scratch.
I teach on my youtube channel hackingsimplified , about cybersecurity stuff.
Available for consulting as well.
Here Comes the second :
Files Leaking Sensitive Info - Be The H.A.C.R. - Ep - 02
HackThisSite - Basic Missions 2 & 3
This episode includes 1. Twitter Info leak - $560 awarded 2. Yahoo info leak - 2 phpinfo pages 3. Boozt info leak. - $60 awarded
Thanks for your feedback. Have done some major improvements regarding the video and audio quality.
Please check this out and give your feedback :)
A few improvements I got in early feedback :
1. Improve on video quality ( doesn't look 1080p )
2. Improve on sound quality
3. Please please decrease jump cuts or at least make them smooth
4. Decrease your screen time : Don't want to see you so much -_-
Have started working on next video, current setup has serious hardware constraints ( recording audio and video from phone ) and lockdown has increased difficulty getting better hardware.
Nevertheless would love to hear your opinions on this. Also let me know what all needs to be improved on technical aspects.
Thanks.