SRE Weekly Issue #321 • 📖 [The CloudSecList] Issue 136 • [tl;dr sec] #131 - Compromising Read-Only Containers, Finding 0days in Enterprise Software • AWS DataSync - 6 updated methods • Amazon Elastic Compute Cloud - 24 updated methods • AWS IoT - 2 updated methods • AWSKendraFrontendService - 1 updated methods • How to use new Amazon GuardDuty EKS Protection findings • workspaces: 1 updated condition • shield: 1 updated condition • sqlworkbench: 1 new action | 1 updated condition • 🔒 Tool: SSH No Ports SSH to a remote Linux host/device without that device having any open ports (not even 22) on external interfaces All network connectivity is outbound No need to know the target's IP By <a href="https://twitter.com/atsigncompany" target="_blank">@atsigncompany</a> <a href="https://t.co/ASampjUMqV" target="_blank">github.com/atsign-foundat…</a> • 🥶 Frostbyte A POC project that combines different defense evasion techniques to build better <a href="https://twitter.com/hashtag/redteam" target="_blank">#redteam</a> payloads ➡️ Embed an encrypted shellcode stub into a known signed executable &amp; still keep it signed like how the Zloader malware did By <a href="https://twitter.com/0xpwnisher" target="_blank">@0xpwnisher</a> <a href="https://t.co/bZeEtWIVnS" target="_blank">github.com/pwn1sher/frost…</a> • 8.5 years…completed it! Worked Hard, Had Fun, Made History ✅ Friday was my last day <a href="https://twitter.com/awscloud" target="_blank">@awscloud</a> - made so many amazing friends and lifelong memories🧡 ✌️ • Does anyone know why AWS KMS seems to also be called the Trent Service? Who's Trent? • There is a threat actor that is scanning and exploiting AWS environments that are not enforcing IMDSv2, and are running vulnerable software. Reminder: there are vendors that do not allow enforcing IMDSv2 that need to release fixes (including AWS): <a href="https://t.co/TgDSupBAfG" target="_blank">github.com/SummitRoute/im…</a> • I think we have an answer (a few, actually) already. The twitterverse is magic • I’m happy to share that I’m starting a new position as Director of Engineering &amp; Distinguished Engineer <a href="https://twitter.com/showpad" target="_blank">@showpad</a> Very excited to be joining a customer focused, high-growth SaaS organisation 🚀 P.S - We are hiring (DMs open) 😜 • Important parts of Heroku were hacked. 😬 "a threat actor ... downloaded stored customer GitHub integration OAuth tokens ... exfiltrate the hashed and salted passwords for customers’ user accounts" • Just asked "How do I add line numbers to a word doc?" Line number vs no line number has been a hot topic for debate throughout my AWS career. I am finally making the leap! Let's hope this works out. • Yet another dependency takeover - this one in Ruby gems. <a href="https://twitter.com/hashtag/SupplyChainSecurity" target="_blank">#SupplyChainSecurity</a> <a href="https://t.co/7VFlwTJV77" target="_blank">github.com/rubygems/rubyg…</a> • Website to PDF using AWS Lambda Function URLs and CDK • Dear AWS - Please stop your VPN Client from fucking with my networking settings • Need Advice - 75 printers requesting our APIs 200 million times • At what point does glacier make sense? Got hit with a big transfer fee • Accidentally created a bunch of instances in EC2... how much will I get charged? (free tier) • New update from Google's Threat Analysis Group finds numerous APTs running campaigns in Ukraine and Est. Europe, including Fancy Bear (Russia), Ghostwriter (Belarus) and Curious Gorge (China). • CloudFlare Pages, part 1: The fellowship of the secret • GPCS (GIAC Public Cloud Security) • Secure Your Migration to AWS, Part I: The Challenges – TechEconomy.ng - TechEconomy.ng • Contrast Security Embarks on AWS Summit Global World Tour - PR Newswire
9
Monday May, 2022
AWS DataSync - 6 updated methods
May 5
AWS DataSync now supports a new ObjectTags Task API option that can be used to control whether Object Tags are transferred.
Amazon Elastic Compute Cloud - 24 updated methods
May 5
Amazon EC2 I4i instances are powered by 3rd generation Intel Xeon Scalable processors and feature up to 30 TB of local AWS Nitro SSD storage
AWS IoT - 2 updated methods
May 5
AWS IoT Jobs now allows you to create up to 100,000 active continuous and snapshot jobs by using concurrency control.
AWSKendraFrontendService - 1 updated methods
May 5
AWS Kendra now supports hierarchical facets for a query. For more information, see https://docs.aws.amazon.com/kendra/latest/dg/filtering.html
How to use new Amazon GuardDuty EKS Protection findings
Marshall JonesMay 6
If you run container workloads that use Amazon Elastic Kubernetes Service (Amazon EKS), Amazon GuardDuty now has added support that will help you better protect these workloads from potential threats. Amazon GuardDuty EKS Protection can help detect threats related to user and application activity that is captured in Kubernetes audit …
workspaces: 1 updated condition
May 7
1 updated condition: aws:TagKeys (type)
shield: 1 updated condition
May 6
1 updated condition: aws:TagKeys (type)
sqlworkbench: 1 new action | 1 updated condition
May 6
1 new action: UpdateAccountExportSettings (Grants permission to update account-wide export settings); 1 updated condition: aws:TagKeys (type)
clintgibler
Clint Gibler @clintgibler

🔒 Tool: SSH No Ports

SSH to a remote Linux host/device without that device having any open ports (not even 22) on external interfaces

All network connectivity is outbound

No need to know the target's IP

By @atsigncompany

github.com/atsign-foundat…

67May 03 · 7:00 PM
clintgibler
Clint Gibler @clintgibler

🥶 Frostbyte

A POC project that combines different defense evasion techniques to build better #redteam payloads

➡️ Embed an encrypted shellcode stub into a known signed executable & still keep it signed like how the Zloader malware did

By @0xpwnisher

github.com/pwn1sher/frost…

70May 06 · 9:00 PM
steven_bryen
Steven Bryen @steven_bryen

8.5 years…completed it!

Worked Hard, Had Fun, Made History ✅

Friday was my last day @awscloud - made so many amazing friends and lifelong memories🧡 ✌️

5May 02 · 7:52 PM
__steele
Aidan W Steele @__steele

Does anyone know why AWS KMS seems to also be called the Trent Service? Who's Trent?

18May 09 · 8:00 AM
0xdabbad00
Scott Piper @0xdabbad00

There is a threat actor that is scanning and exploiting AWS environments that are not enforcing IMDSv2, and are running vulnerable software.

Reminder: there are vendors that do not allow enforcing IMDSv2 that need to release fixes (including AWS): github.com/SummitRoute/im…

NaderZaveri
Nader Zaveri @NaderZaveri

Since July 2021, @Mandiant identified exploitation of public-facing web applications by threat actors (UNC2903) to harvest credentials using Amazon’s Instance Metadata Service (IMDS).
mandiant.com/resources/clou…

#aws #imds #cloud #cloudsecurity #incidentresponse #breaches #dfir

30May 04 · 4:48 PM
__steele
Aidan W Steele @__steele

I think we have an answer (a few, actually) already. The twitterverse is magic

ajrudzitis
Aleks Rudzitis @ajrudzitis

@__steele @QuinnyPig Alice, Bob, Carol, Eve,… en.wikipedia.org/wiki/Alice_and…

Trent is the trusted third party.

4May 09 · 8:14 AM
steven_bryen
Steven Bryen @steven_bryen

I’m happy to share that I’m starting a new position as Director of Engineering & Distinguished Engineer @showpad

Very excited to be joining a customer focused, high-growth SaaS organisation 🚀

P.S - We are hiring (DMs open) 😜

2May 09 · 11:24 AM
0xdabbad00
Scott Piper @0xdabbad00

Important parts of Heroku were hacked. 😬
"a threat actor ... downloaded stored customer GitHub integration OAuth tokens ... exfiltrate the hashed and salted passwords for customers’ user accounts"

25May 05 · 3:52 PM
bjohnso5y
Brigid Johnson @bjohnso5y

Just asked "How do I add line numbers to a word doc?" Line number vs no line number has been a hot topic for debate throughout my AWS career. I am finally making the leap! Let's hope this works out.

0May 03 · 11:48 PM
Dear AWS - Please stop your VPN Client from fucking with my networking settings

(Apologies for the ranty-ness, but this is seriously driving me up the wall because I keep having to fix it multiple times a day)

On Ubuntu, every time I connect to the VPN with the AWS VPN Client, it sets net.ipv4.ip_forward=0

This fucks up networking on my machine, particularly Docker …

Need Advice - 75 printers requesting our APIs 200 million times

Hi,

We have an integration with a printer manufacturer and their printers are set up in a way that requests our APIs every second to check if we have a print job available for the given printer.

Unfortunately, the printer manufacturer has not heard of webhooks or sockets and is …

At what point does glacier make sense? Got hit with a big transfer fee

EDIT: going to say this is solved. It was most likely the transfer fee that got us (we have 425M objects from all kinds of different logging systems like aws config, flow logs, etc etc).

Solution: Looking at using intelligent tiering or maybe just zipping logs up once …

Accidentally created a bunch of instances in EC2... how much will I get charged? (free tier)

I was making copies of my main instance and created 7 copies of it.

I immediately stopped them (so that they don't eat up my free hours) but didn't fully delete/terminate them until half an hour later.

I know EC2 gives 750 hours of free usage each month, but I'm …

GPCS (GIAC Public Cloud Security)

Hello Guys! anyone studying for the GPCS? Currently studying CCSK and I cant go with CCSP next due that I dont have enough experience.

Do i need to go train with SANS first for me to take the GPCS?

Thanks!