Securing the Cloud: A Story of Research, Discovery, and Disclosure
ID: a70b145e-73f9-50b8-85b5-f3ce9bfa513e
STIX ID: report--a70b145e-73f9-50b8-85b5-f3ce9bfa513e
Feed Name: Black Hills Infosec Blog
BHIS reports that default HUE installations on AWS EMR clusters allow unauthenticated creation of an administrative user, which can then upload and schedule Oozie shell workflows to execute arbitrary shell scripts on master and worker nodes; this was demonstrated with a msfvenom-generated reverse_bash payload to obtain shells and persist a C2 channel. The blog explains the attack steps, notes hundreds of potentially exposed HUE instances via Shodan, and recommends AWS best practices (private subnets, Kerberos, bastion hosts, secure access to web interfaces) to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
