CheatSheetSeries icon indicating copy to clipboard operation
CheatSheetSeries copied to clipboard

Update: Vulnerable Dependency Management Cheat Sheet with Dependency Confusion

Open righettod opened this issue 3 years ago • 7 comments

What is missing or needs to be updated?

I have found this post about Dependency Confusion attack and I think that it can be interesting to add a section about protection against this attack in the Vulnerable Dependency Management Cheat Sheet.

How should this be resolved?

I propose to add a small section showing some protection that can applied.

Thanks a lot in advance and also thanks a lot for your amazing work on this project ❤️

righettod avatar Apr 25 '21 06:04 righettod

Hey @righettod good idea. Do you want to add it?

mackowski avatar Apr 26 '21 10:04 mackowski

Hello Dominique! This cheatsheet would definitely benefit from an update. We should probably discussing at least 2 different types of /Dependency Confusion/ attacks such as (1) Typosquatting and (2) Squatting on names of future package versions of packages that no longer exist.

We would be thrilled if you have time to add a section on this material! I also encourage your students to send us PR's when they see any mistakes!

Aloha, Jim

jmanico avatar Apr 27 '21 13:04 jmanico

I'm eager to see this work done

jmanico avatar May 12 '21 13:05 jmanico

Hello @jmanico and @mackowski

Thanks a lot for the feedback about this proposal.

Unfortunately, i'm very busy on the MSTG and OSHP projects so it will not be possible for me to work on this task.

I apologize again a lot for my decline.

Thanks again for your work on this amazing project 💯

righettod avatar May 15 '21 07:05 righettod

Hey @righettod @jmanico - I have some independent study time where I'll be focusing on dependency management in the next couple of weeks - I can pick this up (and of course if anybody else wants to collaborate/help!). I have a lot of resources that would be of use to this section.

nekosoft avatar Dec 18 '22 12:12 nekosoft

Awesome! @nekosoft I will assign this issue to you and feel free to create a PR for this! We will help, do not worry :)

mackowski avatar Dec 20 '22 09:12 mackowski

@nekosoft and you still interested to make a small PR?

mackowski avatar Jun 13 '23 12:06 mackowski