Exciting day @AbertayCyber!
We had the pleasure of hosting a guest lecture from @diej_99 from @Skyscanner, who shared their insights on bug bounty programmes.
A great opportunity for future security pros to learn from real-world practices!
@StopForumSpam@rootsecdev is it? i guess there's a trade off between security and enabling teams by letting them deploy the resources they need. guardrails in deployments seems another alternative ,one that scales better IMO. having said this, visibility and ownership are still big problems to solve
Lennart Poettering intends to replace "sudo" with systemd's run0. Here's a quick PoC to demonstrate root permission hijacking by exploiting the fact "systemd-run" (the basis of uid0/run0, the sudo replacer) creates a user owned pty for communication with the new "root" process.