Skip to content

Commit b57f84e

Browse files
authored
Add a subtitle
1 parent cd3c5cf commit b57f84e

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

Gathering-weak-npm-credentials.md

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,9 @@
11
# Gathering weak npm credentials
22

3+
_Or how I obtained publish access to 13% of npm packages (including popular ones)._
4+
5+
---
6+
37
In this post, I speak about three ways of gathering credentials — bruteforce attack, known accounts leaks from other sources (not npm), and npm credentials leaks on GitHub (and other places). _The last one was already covered in the [previous post](Do-not-underestimate-credentials-leaks.md), but it's still a valid source nowadays nevertheless._
48

59
Also check out the npm, Inc [blog post](http://blog.npmjs.org/post/161515829950/credentials-resets) about this, if you haven't seen it already.

0 commit comments

Comments
 (0)