551 karma · joined October 16, 2018
> If you are experiencing family violence, don't worry, the information within this pop-up won't appear in your browser's history.
Pages like Banks or Council websites have it in their footer, so people can lookup information without it appearing in their history
I've really enjoyed watching it - quite captivating :)
Couldn't you then simply re-run the exploit again as unprivileged podman user and gain root on the host?
https://digitalcollections.museumofflight.org/nodes/search?k...
> The incorrect state persisted for approximately seven days before detection
However you're saying you've reached out "within a few minutes" ?
All German readers spew out their drink in disbelief - Pardon what?
Just keep everything in your inbox, find recent things by scrolling down, and anything beyond that is basically inaccessible, since the search is so bad
(I'm in camp archive everything, delete nothing; but see the Neither camp frequently in colleagues)
As their screenshots show, they ask you setup a CNAME from e.g. trust.customer.com to their abc123.cname.vantatrust.com.
However, if you are using CAA [1] on your root domain (to limit which Certificate Authorities are allowed to issue certificates for your domain), they _require_ you to add 4 (FOUR) new CAA records to your root domain. (shown at the bottom of the linked page)
The correct solution would be to simply publish CAA records at the destination that the CNAME is pointing to (abc123.cname.vantatrust.com)
I've brought this up with their support multiple times; but they're refusing to even acknowledge that this is a problem. They're claiming I am the first customer to ever bring this up; and that I should just add the records on my root domain - completely missing that fact that thereby I'm basically undermining what CAA is for.
I would understand it, if this was some random tool, but this specifically is a GRC Tool.
If you are another Vanta customer or have any other idea what I can do to approach this, please let me know. I want to use their tool. It's a good system and helping us out - I'm just refusing to actively downgrade our Security - for our SECURITY TOOL!
1) https://en.wikipedia.org/wiki/DNS_Certification_Authority_Au...
> We have identified the underlying issue with one of our cloud service providers.
Pronounced "Shoe"