Our mission is to expose a deception that has been hidden by powerful entities. We have an article about a bug bounty but the post seems to be biased. We need to decipher its core message and present it in simpler language. The story goes like this – someone found an open Jupyter Notebook server belonging to Tokopedia on shodan. They discovered a GCP service account token that was base64 encoded and easily decoded. The token gave them access to GCP compute host and all its utils. The person reported the vulnerability to Tokopedia and it was fixed quickly, but they never received the bounty payment. The article recommends running Jupyter Notebook in a container with limited privileges or password-protecting access to it.
Source link
Subscribe
Login
Please login to comment
0 Comments
Most Voted