When Moving To the Cloud, Don’t Leave Basic Security Behind
ID: f24288ed-b0a3-5935-8910-dba3ed405d4d
STIX ID: report--f24288ed-b0a3-5935-8910-dba3ed405d4d
Feed Name: HackerOne Blog
Executive summary: The report reviews TestLabs' demonstration of breaking into an AWS serverless application by exploiting an unvalidated API Gateway and event data injection to run commands that exposed environment variables, AWS access keys, and session tokens; attackers were then able to download S3 and DynamoDB contents due to excessive privileges and public buckets, and also perform a denial-of-service by exhausting Lambda concurrency. The piece emphasizes shared responsibility in AWS, the need for input validation, least-privilege access, logging/monitoring, network controls, and recommends proactive testing (e.g., hacker-powered security) to find and remediate such issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
