Commit Graph

6 Commits

Author SHA1 Message Date
87bcda9a2a Missions/Equipe 2026-01-10 11:38:21 +01:00
f9a61b566b Missions/Equipe 2026-01-10 11:25:39 +01:00
54c7990ed8 Correction signin 2026-01-10 11:13:53 +01:00
f682af6c10 Clean up: Remove Electron configuration 2026-01-10 11:09:16 +01:00
ecf92f7762 SECURITY: Remove backdoor from next.config.mjs
- Removed malicious userConfig loader that dynamically imported external config
- Removed mergeConfig function that allowed configuration hijacking
- Added .gitignore rules to block v0-user-next.config files

SECURITY INCIDENT:
- Backdoor discovered allowing remote code execution via /adfa route
- Attacker installed cryptocurrency miner on production VM
- Root-level system compromise with 9+ months of access
- Full incident details in SECURITY_INCIDENT_REPORT.md

All malware removed from VM. All credentials being rotated.

Date: January 10, 2026
2026-01-10 10:51:15 +01:00
bcf7832d74 Initial commit 2026-01-09 21:06:52 +01:00