CSP for Pentesters: Faamuyali jɔnjɔnw
Kow fɔcogo
Mewayz Team
Editorial Team
Mun na Pentester bɛɛ ka kan ka kɔnɔkow lakanani sariya dɔn
Kɔnɔkow lakanani sariya (CSP) kɛra navigatɔrɔn fan fɛ lafasali fɛɛrɛ kɔrɔlen dɔ ye ka ɲɛsin cross-site scripting (XSS), data injection ani clickjacking binkanniw ma. O bɛɛ n’a ta, doncogo sɛgɛsɛgɛli baarakɛtaw la, CSP kunkankow bɛ to lakana kɔlɔsiliw dɔ ye minnu ka teli ka labɛn cogo jugu la — ani minnu tɛ faamuya ka ɲɛ. San 2024 sɛgɛsɛgɛli dɔ min kɛra ka siti miliyɔn 1 ni kɔ sɛgɛsɛgɛ, o y’a jira ko 12,8% dɔrɔn de ye CSP kunkankow bila sen kan hali dɔɔnin, wa o la, 94% ɲɔgɔn na, politiki barikantanya kelen dɔrɔn de bɛ yen min bɛ se ka nafa sɔrɔ. Pentesters fɛ, CSP faamuyali tɛ ŋaniyata ye — o ye danfara ye surface-level jateminɛ ni rapɔɔri cɛ min bɛ tiɲɛ na kiliyan ka lakana jɔyɔrɔ barika bonya.
I mana ɛntɛrinɛti baarakɛminɛnw jateminɛw kɛ, ka bug bounty hunting kɛ, walima ka lakana jɔ jagokɛyɔrɔ la min bɛ kiliyanw ka kunnafoniw sɛgɛsɛgɛlenw ɲɛnabɔ, CSP dɔnniya ye jusigilan ye. Nin gafe in bɛ CSP ye min ye, a bɛ baara kɛ cogo min na hood jukɔrɔ, a bɛ dɛsɛ yɔrɔ min na, ani pentesterw bɛ se ka politiki barikamaw jateminɛ cogo min na cogo labɛnnen na ani k’u tɛmɛn.
Kɔnɔkow lakanani sariya bɛ min kɛ tiɲɛ na
A kɔnɔko la, CSP ye lakanani fɛɛrɛ ye min bɛ lase HTTP jaabi kuncɛlen fɛ (walima a ka dɔgɔ, taamasiyɛn fɛ). A bɛ navigatɔrɔn bila ka kunnafoni sɔrɔyɔrɔ minnu — sɛbɛnniw, cogoyaw, jaw, sɛbɛnnibolow, karamɔgɔw, ani fɛn wɛrɛw — minnu bɛ se ka doni ani ka baara kɛ ɲɛ dɔ kan. Ni nafolomafɛn dɔ ye sariya tiɲɛ, navigatɔrɔ b’a bali ani a b’a fɛ ka sariya tiɲɛni fɔ labanyɔrɔ dɔ la.
CSP kɔfɛ dusu fɔlɔ tun ye ka XSS binkanniw nɔgɔya . XSS lafasali laadalata i n’a fɔ donnakow saniyali ani bɔli kodɔn, olu bɛ baara kɛ nka u bɛ kari — sigida kelen min ma sɔrɔ walima kodɔn fili bɛ se ka nɔgɔya don kokura. CSP bɛ lafasali-yɔrɔ dɔ fara a kan : hali ni binkannikɛla dɔ ye sɛbɛnnikɛlan jugu dɔ pikiri DOM kɔnɔ, sariya min labɛnna ka ɲɛ, o bɛ navigatɔrɔ bali k’a kɛ.
CSP bɛ baara kɛ ni sɛbɛn finman modɛli ye. Sani a k’a ɲini ka kunnafoni-jugu dɔntaw bali, a bɛ min ɲɛfɔ k’a jɛya, min bɛ se ka kɛ. Fɛn tɔw bɛɛ bɛ ban ka da a kan. Nin lakana misali in jiginni in fanga ka bon hakilina ta fan fɛ, nka waleyali la, ka politiki gɛlɛnw mara ɛntɛrinɛti baarakɛminɛn gɛlɛnw kɔnɔ — kɛrɛnkɛrɛnnenya la, ɛntɛrinɛti yɔrɔ minnu bɛ modulu tan ni caman ɲɛnabɔ minnu bɛ ɲɔgɔn kan i n’a fɔ CRM, fatura, jateminɛ, ani jatebɔ siraw — o tɔgɔ bɔra kosɛbɛ.
CSP kunkolo dɔ farikololabɔli : cikanw ni sɔrɔyɔrɔw
CSP kuncɛlan dɔ bɛ kɛ ni cikanw ye , minnu kelen-kelen bɛɛ bɛ nafolo suguya kɛrɛnkɛrɛnnen dɔ kɔlɔsi . Nin cikan ninnu faamuyali nafa ka bon pentester bɛɛ bolo min bɛ laɲini dɔ ka politiki jateminɛ. Ladilikan minnu nafa ka bon kosɛbɛ olu ye default-src (cikan o cikan min ma sigi sen kan k’a jɛya), script-src (JavaScript waleyali), style-src (CSS), img-src (jaw), connect-src (XHR, Fetch, WebSocket jɛɲɔgɔnyaw), frame-src (iframes minnu bɛ don a kɔnɔ), ani object-src (plugins i n’a fɔ Flash walima Java applets).
cikan kelen-kelen bɛɛ bɛ sɔn sɔrɔ-fɔcogo kelen walima caman ma minnu bɛ bɔyɔrɔ yamaruyalenw ɲɛfɔ . Olu bɛ daminɛ jatigila tɔgɔ kɛrɛnkɛrɛnnenw na (https://cdn.example.com) ka se daɲɛ kolomaw ma minnu ka bon kosɛbɛ:
- 'yɛrɛ' — a bɛ sira di nafolo ma ka bɔ bɔyɔrɔ kelen na ni sɛbɛn ye
- 'ne si' — o bɛ o suguya nafolo bɛɛ bali
- 'unsafe-inline' — a bɛ sira di inline sɛbɛnniw walima cogoyaw ma (a bɛ XSS lakanani tiɲɛ kosɛbɛ)
- 'unsafe-eval' — bɛ sira di eval(), setTimeout(string), ani o ɲɔgɔnna kode dinamiki waleyali ma
- 'nonce-{random}' — bɛ sira di inline sɛbɛnni kɛrɛnkɛrɛnnenw ma minnu taamasiyɛn bɛ kɛ ni nonce cryptographic nonce ye min bɛ bɛn ɲɔgɔn ma
- 'strict-dynamic' — a bɛ da sɛbɛnnibolow la minnu doni bɛ sɛbɛnnikɛlanw fɛ minnu dalen bɛ u la kaban , ka jatigila basigilenw ka yamaruyasɛbɛnw jate
- donanw : — a bɛ sira di kunnafonidilanw URIw ma i n’a fɔ kɔnɔkow sɔrɔyɔrɔw
CSP kunkanko lakika bɛ se ka kɛ nin cogo la : Kɔnɔkow-Lakanali-Politiki: default-src 'yɛrɛ'; script-src 'yɛrɛ' https://cdn.jsdelivr.net 'kɔrɔ-abc123'; style-src 'yɛrɛ' 'safe-inline'; img-src * ye; fɛn-src 'fɛn si tɛ'. i n' a fɔ pentester , i ka baara ye ka nin sariya in kalan k' a dɔn joona a barika ka bon yɔrɔ min na , a barika ka dɔgɔ yɔrɔ min na , ani a bɛ se ka nafa sɔrɔ yɔrɔ min na .
CSP labɛncogo jugu minnu bɛ kɛ tuma caman na Pentesterw ka kan ka laɲini
danfara min bɛ CSP kunkanko dɔ bilali ni nafama CSP kuncɛlan bilali cɛ , o ka bon kosɛbɛ . Tiɲɛ na, barikantanya dɔw bɛ politiki fanba kɔnɔ minnu bɛ don baarakɛlaw ka nɔgɔya fɛ, mɔgɔ sabananw ka jɛɲɔgɔnya fɛ, walima faamuyabaliya nɔgɔman fɛ. Jateminɛw senfɛ, pentɛriw ka kan ka nin dɛsɛw lajɛ cogo labɛnnen na.
labɛnbaliya min ka jugu kosɛbɛ , o ye 'unsafe-inline' sɔrɔli ye script-src cikan kɔnɔ . Nin daɲɛ koloma kelen in bɛ CSP ka XSS kɛlɛli nafa bɛɛ kɛ nafa tɛ min na a jɔyɔrɔba la, bawo a b’a to navigatɔrɔ bɛ se ka taamasiyɛn suguya bɛɛ kɛ inline kɔnɔ — XSS nafalan bɛna min pikiri tigitigi. O bɛɛ n’a ta, CSP bɛ yɔrɔ minnu na, olu 87% ɲɔgɔn bɛ ‘unsafe-inline’ don u ka script-src kɔnɔ, ka kɛɲɛ ni ɲininiw ye minnu bɔra Google ka lakanajɛkulu fɛ. O cogo kelen na, 'unsafe-eval' bɛ da wuli kode waleyali la ni sɛrɛ-ni-kode baarakɛcogo ye, binkannikɛlaw bɛ se ka minnu cakɛda ni DOM-based pikiriyɔrɔw ye.
Jatigila yamaruyasɛbɛn minnu ka bon kojugu, olu ye sanubɔyɔrɔ wɛrɛ ye. CDN yɔrɔ bɛɛ lajɛlen ka lisi jɛlen don i n’a fɔ *.googleapis.com walima *.cloudflare.com, o kɔrɔ ye ko nafolo o nafolomafɛn min bɛ o yɔrɔw kan, o bɛ kɛ sɛbɛnnikɛlan sɔrɔyɔrɔ ye min bɛ se ka da a kan. Binkannikɛlaw bɛ se ka JavaScript juguw bila o baarakɛminɛnw kɔnɔ ani k’a to a ka baara kɛ laɲini ka lakana kɔnɔ. Baarakɛminɛn minnu bɛ i n’a fɔ CSP Evaluator (min dabɔra Google fɛ) bɛ se ka teliya ka nin sɛbɛnniw jira minnu bɛ yamaruya kojugu. Pentesters ka kan fana ka kungo kɔnɔ sɔrɔyɔrɔw ɲini (*), object-src dantigɛli minnu tununna, ani base-uri ani form-action cikanw tɛ yen — vecteur fila minnu bɛ to ka ye ka ban walasa ka kunnafoniw bɔ kɛnɛ kan walima ka foroko cilenw minɛ.
CSP Bypass Fɛɛrɛ waleyali
Ni pentester ye CSP politiki dɔ jira sɛgɛsɛgɛli senfɛ , o nata ye k' a dɔn n' a bɛ se ka tɛmɛn . Fɛɛrɛ damadɔ bɛ yen minnu sɛbɛnnen don koɲuman, wa u waleyacogo bɛɛ bɛ bɔ cikan kɛrɛnkɛrɛnnenw ni sɔrɔyɔrɔ jiracogo la laɲini ka politiki kɔnɔ.
yeye"Kɔnɔkow lakanani sariya barika ka bon dɔrɔn i n'a fɔ a ka cikan barikama. Soso jiracogo kelen min bɛ sira di kojugu, o bɛ se ka politiki barikama dɔ bɔ kɛnɛ kan — wa pentesters ko dɔnbagaw b'a dɔn tigitigi u bɛ se ka yɔrɔ min lajɛ."
💡 DID YOU KNOW?
Mewayz replaces 8+ business tools in one platform
CRM · Invoicing · HR · Projects · Booking · eCommerce · POS · Analytics. Free forever plan available.
Start Free →
JSONP labanko juguya ye bypass fɛɛrɛ dɔ ye min bɛ se ka da a kan . Ni CSP ye domani dɔ lisi finman ye min bɛ JSONP labanyɔrɔ dɔ jate (misali la Google API caman), binkannikɛla bɛ se ka weleli segin paramɛtiri dɔ dilan min bɛ JavaScript a yɛrɛ sago kɛ. Misali la, ni script-src kɔnɔ accounts.google.com bɛ yen, JSONP labanyɔrɔ min bɛ /o/oauth2/revoke?callback=alert(1) la, o bɛ se ka kɛ sɛbɛnnikɛlan sɔrɔyɔrɔ ye. Pentesters ka kan ka domaines blancs bɛɛ jate ani ka u kelen-kelen bɛɛ lajɛ JSONP, Angular library hosting (min bɛ se ka template injection kɛ ng-app fɛ), walima open redirect vulnerabilities minnu bɛ se ka cakɛda ni script-src allowlists ye.
Basi URI minɛni bɛ baara kɛ ni politiki ma base-uri cikan sɔrɔ . Ni
Bi baarakɛminɛnw kama minnu bɛ baara kɛ ni CSP ye min sinsinnen tɛ siɲɛ kelen kan, pentesterw ka kan ka nonce reuse (nonces minnu tɛ Changé ɲininiw ni ɲɔgɔn cɛ), nonce leakage ɲini fili ɲɛw fɛ walima jaabiw cakɛda fɛ, ani sababuw ka fɛnw pikiri kɛ sɛbɛnnibolo finmanw kɔnɔ minnu bɛ yen DOM manipulation fɛ. Script gadgets — script sariyalenw minnu dalen bɛ u la kaban politiki fɛ minnu bɛ se ka wajibiya ka donnakow kɛ minnu bɛ binnkanni ɲɛminɛ — olu bɛ laala bypass suguya jira min ka gɛlɛn kosɛbɛ, wa a bɛ ɲini ka dɔn kosɛbɛ laɲini ka JavaScript codebase la.
CSP jateminɛ fɛɛrɛ dɔ jɔli
CSP jateminɛ nafama bɛ fɛɛrɛ sigilen de wajibiya sanni ka sɛgɛsɛgɛli kɛ waati dantigɛlen na. Pentesterw ka kan ka CSP sɛgɛsɛgɛli don u ka ɛntɛrinɛti baarakɛminɛnw sɛgɛsɛgɛli baarakɛcogo jɔnjɔn na, k’a daminɛ ni sɛgɛsɛgɛli kɛcogo ye min tɛ kɛ ka ɲɛ, ka taa ɲɛ ka se nafabɔcogo cɛsirilenw ma.
A daminɛ ni CSP kunkankow ni meta taamasiyɛnw bɛɛ lajɛlen ye baarakɛminɛn kɔnɔ. Politikiw bɛ se ka ɲɔgɔn ta labanyɔrɔw ni ɲɔgɔn cɛ — ɲɛmɔgɔjɛkulu bɛ se ka kɔlɔsili gɛlɛnw kɛ ka tɛmɛ jago landingɛ ɲɛ kan, walima a kɔfɛ. Baara kɛ ni navigatɔrɔn dilanni baarakɛminɛnw ye, Burp Suite ka jaabi sɛgɛsɛgɛli, walima cikan-sɛbɛn baarakɛminɛnw i n’a fɔ curl -I walasa ka kunkankow minɛ. Politiki kɛrɛnkɛrɛnnen kelen-kelen bɛɛ balo jateminɛminɛnw kɔnɔ minnu bɛ kɛ otomatiki la: Google ka CSP Evaluator, Mozilla ka Observatory, ani csp-bypass marayɔrɔ GitHub kan, olu bɛɛ bɛ jateminɛ fɔlɔ teliyalenw di.
O kɔfɛ, i ka politiki karti ka kɛɲɛ ni baarakɛminɛn ka nafolo doni kɛcogo yɛrɛ ye. Yala sɛbɛnni dɔw bɛ yen minnu bɛ doni ka bɔ domaniw na minnu tɛ lisi finman kɔnɔ (o b’a jira ko sariya bɛ se ka kɛ kunnafoni dɔrɔn cogo la walima a tɛ waleya) wa? Yala baarakɛminɛn in bɛ a jigi da kosɛbɛ inline scripts kan minnu bɛna kari sariya gɛlɛn dɔ kɔnɔ — k’a jira ko baarakɛlaw bɛ se ka CSP lajɔ walasa ka baarakɛcogo sabati wa? Ka ɲɛsin plateformew ma minnu ka architectures gɛlɛnw — miiri jago ɲɛnabɔli baarakɛminɛnw na ni modules integrales ye minnu bɛ analytics dashboards, lajɛ bolodacogo, wari saracogo, ani jɛkulu ka jɛkafɔ — ka CSP sirilen mara fɛn bɛɛ kan, o ye injiniyɛri gɛlɛya lakika ye. Pentesters ka kan k’u janto kosɛbɛ fɛnw na minnu farala kɔsa in na walima mɔgɔ sabananw ka jɛɲɔgɔnyaw kan, bawo a ka c’a la, olu de ye politiki danfara dɔw don sen kan.
- CSP kunkankow minɛni ani k'u katalogu ka bɔ labanyɔrɔ kɛrɛnkɛrɛnnen bɛɛ la ani jaabi suguya bɛɛ la
- Ka politiki sɛgɛsɛgɛli otomatiki kɛ ni CSP Evaluator ni o ɲɔgɔnna baarakɛminɛnw ye
- Ka yɔrɔ jɛlenw bɛɛ jate JSONP labanyɔrɔw, Angular gafemarayɔrɔw, ani da wulilenw ye
- Sɛgɛsɛgɛli kɛ walasa ka se ka fɔ ka ɲɛ, ka baara kɛ kokura, walima ka bɔgɔ bɔ politiki siratigɛ la minnu ma sigi sen kan
- A sɛgɛsɛgɛ ko kunnafoni dɔrɔn cogoya tɛ fili cogo la min bɛ waleya
- A ɲini ka tɛmɛsira fɛɛrɛ sɛbɛnnenw kɛ ka barikantanya dɔntaw kɛlɛ
- Sɛbɛn sɔrɔlenw ni ɲɛnabɔli bilasiralikan ye, ka fara cikan kɛrɛnkɛrɛnnenw caman cili kan
CSP sɔrɔlenw minnu bɛ se ka waleya, olu sɛbɛnni Pentest rapɔɔriw kɔnɔ
CSP barikantanya dɔnni ye baara tilancɛ dɔrɔn ye — k’u lase yiriwali jɛkuluw ma ka ɲɛ, o de b’a jira n’u bɛ ɲɛnabɔ tiɲɛ na. Sɔrɔ min b'a Fɔ dɔrɔn ko "CSP allows unsafe-inline" ni contexte tɛ, a ka c'a la, o bɛna Bɔ jɔyɔrɔ fɔlɔ la. O nɔ na, pentɛsikɛlaw ka kan ka barikantanya kelen-kelen bɛɛ ka nɔ jɛlen jira u kɛtɔ k’a siri ni cakɛda ye ni XSS vektɔri lakika walima teori ye min kɛrɛnkɛrɛnnen don laɲini waleyali ma.
Aw ka CSP sɔrɔlenw sigi senkan walasa ka sisan politiki (daɲɛ kɔnɔ), cikan kɛrɛnkɛrɛnnen walima sɔrɔyɔrɔ jiracogo min bɛ se ka tiɲɛ, hakilina dalilu min bɛ nafabɔcogo jira walima binkanni lakali jɛlen, ani politiki labɛncogo ladilikan. Ni a bɛ se ka kɛ, yiriwali jɛkulu ka kan ka kuncɛ tigitigi min bila sen kan, o di. Jɛkulu minnu bɛ ɛntɛrinɛti baarakɛminɛn gɛlɛnw baara — yɔrɔ minnu bɛ i n’a fɔ Mewayz minnu bɛ CRM, fatura, sarako, HR ɲɛnabɔli, ani modulu tan ni caman wɛrɛw fara ɲɔgɔn kan ka kɛ ɲɔgɔndan kelen ye baarakɛla 138.000 ni kɔ kama — CSP labɛnni ladilikanw ka kan ka jateminɛ kɛ mɔgɔ sabananw ka jɛɲɔgɔnyaw bɛɛ lajɛlen na ani kɔnɔkow doni fangama. Politiki min ka jugu kojugu, o bɛna baarakɛcogo tiɲɛ; min bɛ sira di kojugu, o bɛ dannaya nkalonma di.
A laban na , CSP tɛ warijɛ marifa ye , wa pentɛriw ka kan k' a frame ka kɛɲɛ n' o ye u ka kunnafoniw kɔnɔ . O ye layini barikama ye lafasali-kɔnɔ-fɛɛrɛ kɔnɔ min bɛ baara kɛ ka ɲɛ ni donnakow tiɲɛni barikama ye, bɔli kodeli, nafolo fitininw dafalen (SRI), ani yiriwali walew lakananenw. Jɛkulu minnu bɛ CSP sɔrɔ ka ɲɛ, olu b’a minɛ i n’a fɔ politiki ɲɛnama — min bɛ wuli u ka baarakɛcogo kɛrɛfɛ, ka kɔrɔbɔ tuma bɛɛ, wa a tɛ a jigi da ‘unsafe-inline’ kan abada i n’a fɔ sira surun banbali. Pentesterw fɛ, CSP sɛgɛsɛgɛli mastering bɛ kunkolo sɛgɛsɛgɛli kɛcogo kɔrɔ caman sɛmɛntiya ka kɛ fɛn nafamaba dɔ ye min bɛ se ka kɛ ɛntɛrinɛti baarakɛminɛnw jateminɛni bɛɛ la.
Ɲininkali minnu bɛ kɛ tuma caman na
Kɔnɔkow lakanani sariya (CSP) ye mun ye ani mun na pentɛriw ka kan k'u janto ?
Kɔnɔkow lakanani sariya ye navigatɛri fan fɛ lakana fɛɛrɛ ye min bɛ nafolo minnu kɔlɔsi ɛntɛrinɛti yɔrɔ bɛ se ka minnu doni, ka dɛmɛ don ka XSS, kunnafonidilanw pikiri ani digili binkanniw bali. Pentesters ka kan ka CSP faamuya bawo a ye lakana kɔlɔsiliw dɔ ye min ka teli ka labɛn cogo jugu la — kalanw y’a jira ko 94% ɲɔgɔn bɛ politiki bolodalenw na, barikantanya bɛ minnu na minnu bɛ se ka nafa sɔrɔ. CSP jɔnjɔnw dɔnni bɛ pentesters dɛmɛ u ka se ka gɛlɛya juguw dɔn minnu ka teli ka sɔrɔ otomatiki skanɛrɛw fɛ pewu.
CSP labɛnbaliya minnu ka teli ka sɔrɔ pentɛriw fɛ , olu ye mun ye ?
CSP labɛncogo jugu minnu ka teli ka kɛ, olu ye ka baara kɛ ni unsafe-inline ani unsafe-eval cikanw ye, kungo kɔnɔ fɛnw sɔrɔyɔrɔw minnu bɛ sɔn kojugu, frame-ancestors cikanw tunun minnu bɛ se ka digili kɛ, ani ka CDN yɔrɔ bɛɛ lajɛlen kɛ lisi finman ye minnu bɛ binkannikɛla ka kunnafoniw ladon. Pentesters ka kan fana ka cikanw ɲini minnu tununna i n’a fɔ base-uri ani form-action, minnu bɛ se ka kɛ sababu ye ka phishing ni data exfiltration kɛ hali ni script controls bɛ i n’a fɔ a ka gɛlɛn.
jagokɛlaw bɛ se k' u ka ɛntɛrinɛti baarakɛminɛnw lakana cogo di ni CSP kuncɛcogo ɲumanw ye ?
Jagokɛlaw ka kan ka daminɛ ni CSP gɛlɛn ye ka baara kɛ ni script allowlisting ye min sinsinnen tɛ siɲɛ kelen kan walima min sinsinnen bɛ hash kan sanni ka kɛ domain whitelists ye. Deploy in report-only mode fɔlɔ walasa ka karilenw dɔn sani a ka waleya. Plateformes i n’a fɔ Mewayz, n’o ye jagokɛla ka OS ye min bɛ se ka kɛ modulu 207 ye, n’a bɛ daminɛ $19/mo la, o bɛ ekipuw dɛmɛ u k’u ka ɛntɛrinɛti sɔrɔli ɲɛnabɔ lakana la k’a sɔrɔ u bɛ tugu bi lakana wale ɲumanw kɔ nizɛri touchpoint bɛɛ kɔnɔ.
pentɛriw bɛ baara kɛ ni baarakɛminɛn jumɛnw ye walasa ka CSP nafa jateminɛ ?
Pentesters ka teli ka baara kɛ ni Google ka CSP Evaluator ye, navigatɔrɔn dilanni baarakɛminɛnw, ani Burp Suite farankanw ye walasa ka CSP kunkankow sɛgɛsɛgɛ barikantanya kan. Bololabaara kɔrɔbɔli bɛ to wajibi ye — otomatiki baarakɛminɛnw bɛ tɛmɛsira kan minnu bɛ tali kɛ sigida la i n’a fɔ JSONP labanyɔrɔw ani Angular template injection on whitelisted domains. Jateminɛ dafalen bɛ otomatiki sɛgɛsɛgɛli ni bololabaara seginnkanni fara ɲɔgɔn kan ka kɛɲɛ ni bypass fɛɛrɛ dɔntaw ye ani baarakɛminɛn ka fɛɛrɛ kɛrɛnkɛrɛnnenw kulu.
dɔntaw yeTry Mewayz Free
All-in-one platform for CRM, invoicing, projects, HR & more. No credit card required.
Get more articles like this
Weekly business tips and product updates. Free forever.
You're subscribed!
Start managing your business smarter today
Join 30,000+ businesses. Free forever plan · No credit card required.
Ready to put this into practice?
Join 30,000+ businesses using Mewayz. Free forever plan — no credit card required.
Start Free Trial →Related articles
Hacker News
Laravel raised money and now injects ads directly into your agent
Apr 16, 2026
Hacker News
Claude Opus 4.7 Model Card
Apr 16, 2026
Hacker News
There's yet another study about how bad AI is for our brains
Apr 16, 2026
Hacker News
Qwen3.6-35B-A3B: Agentic Coding Power, Now Open to All
Apr 16, 2026
Hacker News
The Future of Everything Is Lies, I Guess: Where Do We Go from Here?
Apr 16, 2026
Hacker News
Cloudflare Email Service: now in public beta. Ready for your agents
Apr 16, 2026
Ready to take action?
Start your free Mewayz trial today
All-in-one business platform. No credit card required.
Start Free →14-day free trial · No credit card · Cancel anytime