Henrik Plate

19 posts

Henrik Plate

Henrik Plate

@HenrikPlate

Researching open source security

Katılım Ekim 2020
23 Takip Edilen68 Takipçiler
Henrik Plate
Henrik Plate@HenrikPlate·
@JPD_1206 @CharlieEriksen @marius_benthin @cyb3rops Thank you for neutralizing the npm packages hosted on npm[.]jpartifacts[.]com — no installation hook and no data harvesting code anymore. But it also shows the risk of using URL dependencies, which place control outside the visibility and versioning guarantees of the registry.
English
0
0
0
73
Marius Benthin
Marius Benthin@marius_benthin·
Another wave of #NPM packages related to #PhantomRaven. New endpoint for remote dynamic dependencies: hxxp://package[.]storeartifacts[.]com/npm/ Packages: clean-order:8.0.0 typescript-urql:8.0.0 google-camelcase:8.0.0 add-react-displayname:0.0.6
Marius Benthin tweet mediaMarius Benthin tweet media
English
4
9
40
5.1K
Henrik Plate
Henrik Plate@HenrikPlate·
@JPD_1206 @CharlieEriksen @marius_benthin @cyb3rops In other words: Why don’t you send a tiny beacon as a proof of installation, through code part of the package itself, instead of collecting way too much through a dynamic dependency that can change at any time.
English
0
0
1
55
Henrik Plate
Henrik Plate@HenrikPlate·
Just today, an article on software supply chain security, written with Wolfram Fischer, got published in the German IT magazine iX. It picks up our works on a taxonomy of supply chain attacks, done together with @piergiorgioLad , @barais and Matias Sebastian Martinez...
English
0
1
7
0
Henrik Plate
Henrik Plate@HenrikPlate·
@joshbressers The survey is done by SAP Security Research and the University of Rennes 1. Results will be published, and the interactive attack tree publicly available, together with associated safeguards. There are many use-cases of the attack tree, from education to scoping/guiding pentests.
English
1
0
0
0
Henrik Plate retweetledi
SPARTA
SPARTA@sparta_eu·
Check out the tools provided by @sparta_eu CAPE program to evaluate the consequences of vulnerabilities in open source libraries on the applications that use them! 🇪🇺📚🔐 🛠sparta.eu/news/2021-04-1…
SPARTA tweet mediaSPARTA tweet media
English
0
6
10
0
Henrik Plate retweetledi
Merve Sahin
Merve Sahin@mervesahin·
We are conducting a small experiment on the use of #deceptive #HTTP parameters to improve #application #security. The questionnaire takes around 30 min, and we would really appreciate your participation! Check out the link for more details➡️ bit.ly/3sSx3Za
English
0
10
3
0