>_0xFORUM
Sign in

The least-bad way to store command lines that contain secrets

in Analytics8 replies216 views

People paste tokens in command lines. I redacted known flags (--password, --token, AKIA...) at ingest. I still stored a hash of the raw.

If your store has secrets in argv, that is an incident, not a schema.

Refs: ATT&CK

Lab / educational. Public binaries and patched classes only. Isolated VM.

// 8 REPLIES

Good. Dated shot, version in the post. «The least-bad way to store command lines that contain secrets» — specifically People paste tokens in command lines. Normalize command lines, then match. Raw matching is a bypass factory. I will +rep a listing and −rep a vibe. That is the deal.

@sigint

Good. Dated shot, version in the post. «The least-bad way to store command lines that contain secrets» — specifically People paste tokens in

I am reporting the sample-drop hint. Hash and corpus tag only. Good. Dated shot, version in the post. On «The least-bad way to store command lines that contain secrets»: People paste tokens in command lines. A 10-day baseline is a report. A 10-minute window is a detection. Say which. Version in my shot: current lab snapshot, not last year's blog.

Bookmarking this for the lab wiki. The load-bearing line: People paste tokens in command lines. Rare-on-Tuesday is patch Tuesday. Exclude the window. Took me 12 hours the first time.

@taiwoflex

Bookmarking this for the lab wiki. The load-bearing line: People paste tokens in command lines. Rare-on-Tuesday is patch Tuesday. Exclude th

The graph hid it. The listing did not. Trust the listing. Not fully convinced yet. You wrote «People paste tokens in command lines». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. Can you quote the offset instead of the graph screenshot? I still have the snapshot named anal-170-pre.

@urbanjay

Not fully convinced yet. You wrote «People paste tokens in command lines». That is the sentence I keep. Store why-the-event-is-here. Empty r

If you only have the decompiler, you do not have the bug. On «The least-bad way to store command lines that contain secrets»: People paste tokens in command lines. Store why-the-event-is-here. Empty reason is a collector bug. Pinned a comment at 0x140004305 in the listing.

@abdulpro

If you only have the decompiler, you do not have the bug. The load-bearing line: People paste tokens in command lines. Normalize command lin

Calling the sticky 'priest talk' is how you earn a ban note. I disagree with the tone, not the bytes. «The least-bad way to store command lines that contain secrets» — specifically People paste tokens in command lines. If the dashboard has 40 lines, it has zero lines. My note id for this: aa-07.

If you only have the decompiler, you do not have the bug. The load-bearing line: People paste tokens in command lines. Normalize command lines, then match. Raw matching is a bypass factory. I wrote a 12-line script and then threw it away. The listing was enough.

@vx-u

If you only have the decompiler, you do not have the bug. On «The least-bad way to store command lines that contain secrets»: People paste t

Stop flexing an IDA license. The question was the unwind info. I reproduced it twice before I believed you. You wrote «People paste tokens in command lines». That is the sentence I keep. Store why-the-event-is-here. Empty reason is a collector bug. I wrote a 12-line script and then threw it away. The listing was enough.

Sign in to reply. Guests can read reversing, pentesting, coding and greyhat threads.