SRE Weekly Issue #282 • 📖 [The CloudSecList] Issue 99 • [tl;dr sec] #95 - Preventing SSRF in AWS, Testing AuthN Flows • AWS Notification Message • Auto Scaling - 2 updated methods • Amazon Lex Model Building V2 - 6 updated methods • Amazon Relational Database Service - 23 updated methods • AWS Systems Manager Incident Manager - 1 updated methods • ec2: 1 updated action • redshift: 8 new actions, 1 new resource, 1 new condition • route53-recovery-cluster: 3 new actions, 1 new resource • route53-recovery-readiness: 32 new actions, 4 new resources, 3 new conditions • Summit Route - S3 backups and other strategies for ensuring data durability through ransomware attacks • tl;dr sec Newsletter • Introducing 79 new resource types in the CloudFormation Registry • You've seen his work before if you've ever done any reverse engineering. He's most well known for his work and expertise in file formats, but is also highly skilled in fuzzing, reverse engineering, and malware analysis. RT for signal boost. • Ensuring your data in S3 buckets can withstand ransomware attacks or similar threats is not as trivial as you might expect. Here is my guidance. <a href="https://t.co/QnKbBsXz4d" target="_blank">summitroute.com/blog/2021/08/0…</a> • If you worry about the security of your GSuite, this video is "mandatory" watching. Awesome work by <a href="https://twitter.com/IAmMandatory" target="_blank">@IAmMandatory</a>. Covers phishing, persistence, lateral movement, accessing data, and doing what is basically Word Macro malware in Google Docs. <a href="https://t.co/hWuYZlszfg" target="_blank">youtube.com/watch?v=6AsVUS…</a> • 🙌 Awesome OPA by <a href="https://twitter.com/anderseknert" target="_blank">@anderseknert</a> et al A curated list of awesome <a href="https://twitter.com/OpenPolicyAgent" target="_blank">@OpenPolicyAgent</a> related tools, frameworks and articles * Language and Platform Integrations * Datasource Integrations * Tools and Utilities * IDE and Editor Integrations * ... <a href="https://t.co/qfaf3ws5GC" target="_blank">github.com/anderseknert/a…</a> • One of the biggest helpers for AWS IAM is using the Service Authorization Reference (SAR) <a href="https://t.co/rYGumGNwuF" target="_blank">docs.aws.amazon.com/service-author…</a> Not all service actions work on all a service's resources, and knowing what works with what is key to avoiding surprises! • Super strong issue of <a href="https://t.co/B7SoUXwvye" target="_blank">CloudSecList.com</a> just went out. I have to say I've been impressed with the quality of articles released this past week. From <a href="https://twitter.com/SummitRoute" target="_blank">@SummitRoute</a>, <a href="https://twitter.com/jcfarris" target="_blank">@jcfarris</a>, <a href="https://twitter.com/Square" target="_blank">@Square</a>, <a href="https://twitter.com/twilio" target="_blank">@twilio</a>, <a href="https://twitter.com/RhinoSecurity" target="_blank">@RhinoSecurity</a>, <a href="https://twitter.com/HashiCorp" target="_blank">@HashiCorp</a> and more <a href="https://t.co/AFNRpuUTPz" target="_blank">cloudseclist.com/issues/issue-9…</a> • Here you have it!❓I am doing an AMA...and by anything I mean anything AWS permissions❓I'll probably answer questions about Pickles🐴too. Looking forward to talking with the folks in <a href="https://twitter.com/AWSUserGroupUK" target="_blank">@AWSUserGroupUK</a> <a href="https://t.co/GhfRmeCJRX" target="_blank">meetup.com/AWSUGUK/events…</a> • Read about my concerns with the new Lightsail object storage and a security issue I discovered that has been fixed. Great work by the team there on resolving this so quickly. <a href="https://t.co/znrpY0nf4O" target="_blank">summitroute.com/blog/2021/08/0…</a> • New Rhino Blog:  Cloud Malware: Resource Injection in CloudFormation Templates <a href="https://t.co/aFPuTb81Wb" target="_blank">bit.ly/3jhABAy</a> • 🪣 Can your S3 buckets withstand ransomware? <a href="https://twitter.com/0xdabbad00" target="_blank">@0xdabbad00</a> describes: * Your two best options: s3 object locks and replication policies * How to use them * What to watch out for <a href="https://t.co/uDCCtiIgtq" target="_blank">summitroute.com/blog/2021/08/0…</a> • Show /r/aws: The Cloud Cost Handbook • DynamoDB outage? • Dealing with DynamoDB Outages • xoto3: a Pythonic, functional library for DynamoDB transactions and atomic updates • Amazon Redshift extends Automatic Table Optimization to support Column Compression Encoding • Proof that snaps from Snapchat don't disappear and can easily be recovered • HTTP/2: The Sequel is Always Worse - more HTTP request smuggling attacks from albinowax • GCP COAT Vulnerable application to learn GCP Security • AWS Cloud Security Summit - Virtualization Review • Researchers Call for 'CVE' Approach for Cloud ... - Dark Reading • Cloud Mission Bets On AWS Cloud Managed Security Services Channel e2e - ChannelE2E
9
Monday August, 2021
Auto Scaling - 2 updated methods
Aug 5
EC2 Auto Scaling adds configuration checks and Launch Template validation to Instance Refresh.
Amazon Lex Model Building V2 - 6 updated methods
Aug 5
Customers can now toggle the active field on prompts and responses.
Amazon Relational Database Service - 23 updated methods
Aug 4
This release adds AutomaticRestartTime to the DescribeDBInstances and DescribeDBClusters operations. AutomaticRestartTime indicates the time when a stopped DB instance or DB cluster is restarted automatically.
AWS Systems Manager Incident Manager - 1 updated methods
Aug 4
Documentation updates for Incident Manager.
ec2: 1 updated action
Aug 7
1 updated action: CreateRoute (resources, conditions)
redshift: 8 new actions, 1 new resource, 1 new condition
Aug 6
8 new actions: AssociateDataShareConsumer (associate a consumer to a datashare), AuthorizeDataShare (authorize the specified datashare consumer to consume a datashare), DeauthorizeDataShare (remove permission from the specified datashare consumer to consume a datashare), DescribeDataShares (describe datashares created and consumed by your clusters), DescribeDataSharesForConsumer (describe only datashares consumed by your clusters), DescribeDataSharesForProducer …
route53-recovery-cluster: 3 new actions, 1 new resource
Aug 6
3 new actions: GetRoutingControlState (get a routing control state), UpdateRoutingControlState (update a routing control state), UpdateRoutingControlStates (update routing control states); 1 new resource: routingcontrol ()
route53-recovery-readiness: 32 new actions, 4 new resources, 3 new conditions
Aug 6
32 new actions: CreateCell (create a new cell), CreateCrossAccountAuthorization (create a new cross account authorization), CreateReadinessCheck (create a new readiness check), CreateRecoveryGroup (create a recovery group), CreateResourceSet (create a new resource set), DeleteCell (delete an existing cell), DeleteCrossAccountAuthorization (delete a cross account authorization), DeleteReadinessCheck (delete an existing readiness check), DeleteRecoveryGroup …
0xdabbad00
Scott Piper @0xdabbad00

You've seen his work before if you've ever done any reverse engineering. He's most well known for his work and expertise in file formats, but is also highly skilled in fuzzing, reverse engineering, and malware analysis. RT for signal boost.

angealbertini
👼 Ąż 杏 @angealbertini

I’m looking for a new position (remote work while being based in Germany or local, based near Bodensee).
Any pointers?

SummitRoute
Summit Route @SummitRoute

Ensuring your data in S3 buckets can withstand ransomware attacks or similar threats is not as trivial as you might expect. Here is my guidance.
summitroute.com/blog/2021/08/0…

0xdabbad00
Scott Piper @0xdabbad00

If you worry about the security of your GSuite, this video is "mandatory" watching. Awesome work by @IAmMandatory.
Covers phishing, persistence, lateral movement, accessing data, and doing what is basically Word Macro malware in Google Docs.
youtube.com/watch?v=6AsVUS…

IAmMandatory
💉💉mandatory/Matthew Bryant @IAmMandatory

Will be giving the talk "Hacking G Suite: The Power of Dark Apps Script Magic" at DEF CON (Track 1) at 3:00 PM PST (start of this coming hour).

If the content seems interesting to you, stop by 👍.

clintgibler
Clint Gibler @clintgibler

🙌 Awesome OPA by @anderseknert et al

A curated list of awesome @OpenPolicyAgent related tools, frameworks and articles

* Language and Platform Integrations
* Datasource Integrations
* Tools and Utilities
* IDE and Editor Integrations
* ...

github.com/anderseknert/a…

elrowan
rowan @elrowan

One of the biggest helpers for AWS IAM is using the Service Authorization Reference (SAR) docs.aws.amazon.com/service-author…

Not all service actions work on all a service's resources, and knowing what works with what is key to avoiding surprises!

lancinimarco
Marco Lancini @lancinimarco

Super strong issue of CloudSecList.com just went out. I have to say I've been impressed with the quality of articles released this past week. From @SummitRoute, @jcfarris, @Square, @twilio, @RhinoSecurity, @HashiCorp and more

cloudseclist.com/issues/issue-9…

bjohnso5y
Brigid Johnson @bjohnso5y

Here you have it!❓I am doing an AMA...and by anything I mean anything AWS permissions❓I'll probably answer questions about Pickles🐴too. Looking forward to talking with the folks in @AWSUserGroupUK
meetup.com/AWSUGUK/events…

SummitRoute
Summit Route @SummitRoute

Read about my concerns with the new Lightsail object storage and a security issue I discovered that has been fixed. Great work by the team there on resolving this so quickly. summitroute.com/blog/2021/08/0…

0xdabbad00
Scott Piper @0xdabbad00

It's been a while since I reported a security issue to AWS. Happy Friday AWS security team. 😀 (It's not too bad, you can wait until Monday to look at it).

RhinoSecurity
Rhino Security Labs @RhinoSecurity

New Rhino Blog:  Cloud Malware: Resource Injection in CloudFormation Templates
bit.ly/3jhABAy

clintgibler
Clint Gibler @clintgibler

🪣 Can your S3 buckets withstand ransomware?

@0xdabbad00 describes:
* Your two best options: s3 object locks and replication policies
* How to use them
* What to watch out for

summitroute.com/blog/2021/08/0…

DynamoDB outage?

Anyone else seeing issues with DynamoDB in east-1? Getting a ton of internal errors and cant list tables on the console.

Update 930 EDT: Confirmed issue from AWS (posted on PHD)

Dealing with DynamoDB Outages

In light of the outage yesterday, how does everyone mitigate outages like this? My databases are currently in RDS, but I've been exploring DynamoDB for future work. It seems like not using us-east-1 is a good first step. Jokes aside, would something like global tables with application level failover be …

xoto3: a Pythonic, functional library for DynamoDB transactions and atomic updates

I'm aware of some other solutions in this space, but I think this one has a few things going for it that others don't.

https://github.com/xoeye/xoto3/tree/develop/xoto3/dynamodb/write_versioned/README.md

The pitch? Don't ever write database mutations that look even remotely like talking to DynamoDB. Just write code that expresses your writes as though you're …

GCP COAT Vulnerable application to learn GCP Security

Hello everyone 📷 I am happy to be release my project that I am working for a long time https://gcpgoat.joshuajebaraj.com/index.html

buymeacoffee