SRE Weekly Issue #309 • 📖 [The CloudSecList] Issue 124 • [tl;dr sec] #119 - Picking the Right Terraform Security Tool, BloodHound for Cloud • AWS CloudFormation - 1 updated methods • Amazon Pinpoint - 4 updated methods • AWS WAFV2 - 3 new 8 updated methods • AWS CloudFormation - 1 new 15 updated methods • C5 Type 2 attestation report now available with 141 services in scope • ds: 1 new action | 4 updated actions • quicksight: 2 new actions • cloudformation: 1 new action • Release v4.0.0 · hashicorp/terraform-provider-aws • 🔎 OAUTHScan A <a href="https://twitter.com/Burp_Suite" target="_blank">@Burp_Suite</a> extension useful when testing applications implementing OAUTHv2 and OpenID standards Contains 10+ security checks for vulnerabilities and common misconfigurations <a href="https://twitter.com/hashtag/bugbountytips" target="_blank">#bugbountytips</a> <a href="https://twitter.com/hashtag/websecurity" target="_blank">#websecurity</a> <a href="https://t.co/T5LVtozqcc" target="_blank">github.com/akabe1/OAUTHSc…</a> • My girlfriend just passed her AWS Certified Solutions Architect Associate exam! I guess we are the cloud couple now 😂 • v4.0.0 of the <a href="https://twitter.com/hashtag/Terraform" target="_blank">#Terraform</a> AWS Provider came out today. It moves the provider to using IMDSv2. If you're running in a container on an EC2 instance you'll need to increase the HttpPutResponseHopLimit to 2. If you don't you'll get errors about "no valid credential sources." • Hey <a href="https://twitter.com/TwitterSupport" target="_blank">@TwitterSupport</a>, please re-enable this account: <a href="https://twitter.com/awswhatsnew" target="_blank">@awswhatsnew</a> It just tweets the links from Amazon's RSS feed. • Finally got around to publishing my first hook! This hook scans all properties of all resources and blocks if secrets are found. You can specify your own rules or use the comprehensive defaults, and even add path-based exceptions. It's available in all regions now.🪝☁️ <a href="https://t.co/GdLofm6aYH" target="_blank">twitter.com/AWSCloudFormer…</a> • 🛡️ Awesome-Security-Hardening A collection of awesome security hardening guides, best practices, checklists, benchmarks, tools &amp; other resources by <a href="https://twitter.com/decalage2" target="_blank">@decalage2</a> * Linux/Windows/macOS * Network devices * Containers * SSH * Web servers + more <a href="https://twitter.com/hashtag/blueteam" target="_blank">#blueteam</a> <a href="https://t.co/Zi1RYW2bCH" target="_blank">github.com/decalage2/awes…</a> • Reminder: GuardDuty's new EKS monitoring has now been disabled for everyone (it had originally been auto-enabled). You need to re-enable it. <a href="https://t.co/IvXlWkPLEl" target="_blank">aws.amazon.com/about-aws/what…</a> • Stratus Red Team v1.4.0 released! New: Kubernetes support, with 4 techniques: • Steal service account token from a pod • Create an admin role • Run a privileged pod • Run a pod mounting the host filesystem 👉<a href="https://t.co/NeWtzlPwpv" target="_blank">github.com/DataDog/stratu…</a> 📈 Next up: More Kubernetes, Azure support • ~HECK~ HOOK YEAH hooks are here! <a href="https://t.co/SB4yN6k3JX" target="_blank">aws.amazon.com/about-aws/what…</a> • Finally managed to read "Scanning Infrastructure-as-Code for security flaws" from <a href="https://twitter.com/christophetd" target="_blank">@christophetd</a>: I have to say I did laugh when I saw this slide :D <a href="https://t.co/ZfsViAbB1j" target="_blank">docs.google.com/presentation/d…</a> • We started using AWS SSO with external apps - there is no api so i had to automate the creation of over 500 apps • Terraform AWS Provider 4.0 • A magical AWS serverless developer experience • Best Practices for AWS Organizations Service Control Policies in a Multi-Account Environment • Introducing AWS Virtual Waiting Room • A simple tool to audit Linux system libraries to find public security vulnerabilities. • Top 10 web hacking techniques of 2021 • AWS Cloud Security challenge - 1 • Best Buy Selects AWS as 'Preferred' Cloud provider - Datamation • Why Create an EKS Creation Tool? - Security Boulevard
14
Monday February, 2022

Scale AWS IAM security (📢 Sponsor)

Securing AWS IAM shouldn’t overload experts. Now you can scale AWS security out to delivery teams.

Eliminate excess IAM privileges with actionable IAM access reports and usable automation from k9 Security. Integrated with your favorite tools.

Built for Cloud teams doing continuous delivery.


📢 MAMIP (Monitor AWS Managed IAM Policies)

Policies changed since last week:


👉🏻 📃 MAMIP / 🤖 MASE / 👮🏻‍♂️ MGDA

AWS CloudFormation - 1 updated methods
Feb 10
This SDK release adds AWS CloudFormation Hooks HandlerErrorCodes
Amazon Pinpoint - 4 updated methods
Feb 10
This SDK release adds a new paramater creation date for GetApp and GetApps Api call
AWS WAFV2 - 3 new 8 updated methods
Feb 10
Adds support for AWS WAF Fraud Control account takeover prevention (ATP), with configuration options for the new managed rule group AWSManagedRulesATPRuleSet and support for application integration SDKs for Android and iOS mobile apps.
AWS CloudFormation - 1 new 15 updated methods
Feb 9
This SDK release is for the feature launch of AWS CloudFormation Hooks.
C5 Type 2 attestation report now available with 141 services in scope
Mercy KanengoniFeb 11
Amazon Web Services (AWS) is pleased to announce the issuance of the new Cloud Computing Compliance Controls Catalogue (C5) Type 2 attestation report. We added 18 additional services and service features to the scope of the 2021 report. Germany’s national cybersecurity authority, Bundesamt für Sicherheit in der Informationstechnik (BSI), established …
ds: 1 new action | 4 updated actions
Feb 14
1 new action: DescribeClientAuthenticationSettings (retrieve information about the type of client authentication for the specified directory, if the type is specified. if no type is specified, information about all client authentication types that are supported for the specified directory is retrieved. currently, only smartcard is supported); 4 updated actions: ConnectDirectory …
quicksight: 2 new actions
Feb 14
2 new actions: AccountConfigurations (to enable setting default access to aws resources), ScopeDownPolicy (scoping policies for permissions to aws resources)
cloudformation: 1 new action
Feb 14
1 new action: DescribeChangeSetHook (return the hook invocation information for the specified change set)
clintgibler
Clint Gibler @clintgibler

🔎 OAUTHScan

A @Burp_Suite extension useful when testing applications implementing OAUTHv2 and OpenID standards

Contains 10+ security checks for vulnerabilities and common misconfigurations

#bugbountytips #websecurity

github.com/akabe1/OAUTHSc…

kmcquade3
Kinnaird McQuade💥🌩 @kmcquade3

My girlfriend just passed her AWS Certified Solutions Architect Associate exam! I guess we are the cloud couple now 😂

BenReser
Ben Reser @BenReser

v4.0.0 of the #Terraform AWS Provider came out today. It moves the provider to using IMDSv2. If you're running in a container on an EC2 instance you'll need to increase the HttpPutResponseHopLimit to 2. If you don't you'll get errors about "no valid credential sources."

0xdabbad00
Scott Piper @0xdabbad00

Hey @TwitterSupport, please re-enable this account: @awswhatsnew It just tweets the links from Amazon's RSS feed.

iann0036
Ian Mckay @iann0036

Finally got around to publishing my first hook!

This hook scans all properties of all resources and blocks if secrets are found. You can specify your own rules or use the comprehensive defaults, and even add path-based exceptions. It's available in all regions now.🪝☁️ twitter.com/AWSCloudFormer…

AWSCloudFormer
AWS CloudFormation @AWSCloudFormer

Announcing #AWS #CloudFormation Hooks! Now you can run custom logic before CloudFormation creates, updates, or deletes a resource in your AWS accounts. Learn more here: go.aws/3BkV6F5

clintgibler
Clint Gibler @clintgibler

🛡️ Awesome-Security-Hardening

A collection of awesome security hardening guides, best practices, checklists, benchmarks, tools & other resources by @decalage2

* Linux/Windows/macOS
* Network devices
* Containers
* SSH
* Web servers

+ more

#blueteam

github.com/decalage2/awes…

0xdabbad00
Scott Piper @0xdabbad00

Reminder: GuardDuty's new EKS monitoring has now been disabled for everyone (it had originally been auto-enabled). You need to re-enable it.
aws.amazon.com/about-aws/what…

christophetd
Christophe @christophetd

Stratus Red Team v1.4.0 released!

New: Kubernetes support, with 4 techniques:
• Steal service account token from a pod
• Create an admin role
• Run a privileged pod
• Run a pod mounting the host filesystem

👉github.com/DataDog/stratu…
📈 Next up: More Kubernetes, Azure support

lancinimarco
Marco Lancini @lancinimarco

Finally managed to read "Scanning Infrastructure-as-Code for security flaws" from @christophetd: I have to say I did laugh when I saw this slide :D
docs.google.com/presentation/d…

AWS Cloud Security challenge - 1

Hey folks,

Starting these random challenges for people to try out and learn cloud hacking. You can start the hunt from s3-challenge-1 bucket. :)

Have fun !

buymeacoffee