SRE Weekly Issue #339 • 📖 [The CloudSecList] Issue 155 • [tl;dr sec] #150 - How to Start an AppSec Program with the OWASP Top 10, Leadership in Cybersecurity • Amazon Elastic Compute Cloud - 11 updated methods • Amazon SageMaker Service - 4 updated methods • AWS Amplify UI Builder - 8 new 4 updated methods • Amazon Elastic Compute Cloud - 8 new 10 updated methods • 10 reasons to import a certificate into AWS Certificate Manager (ACM) • 154 AWS services achieve HITRUST certification • Amazon introduces dynamic intermediate certificate authorities • Use AWS Network Firewall to filter outbound HTTPS traffic from applications hosted on Amazon EKS and collect hostnames provided by SNI • evidently: 6 new actions, 1 new resource | 4 updated resources, 4 updated actions • lookoutequipment: 9 new actions, 1 new resource | 1 updated resource, 3 updated actions • cloudtrail: 5 new actions, 1 new resource | 3 updated actions, 1 updated resource • GitHub - awslabs/aws-security-assessment-solution: An AWS tool to help you create a point in time assessment of your AWS account using Prowler and Scout as well as optional AWS developed ransomware checks. • GitHub - matanolabs/matano: The open-source security lake platform for AWS • Kubernetes API Server Bypass Risks • GitHub - google/magic-github-proxy: An access-limiting stateless GitHub API Proxy • ✨Linux tips 🧵 1. Always remove the french language pack: sudo rm -fr ./* • After using AWS for ~14 years, I've internalised a handful of design patterns that I try to apply to my own software. I'm keen to know if it's the same for other folks. Roughly: tags, IDs (thrice), limits, pagination. (I'm not going to use the thread emoji) • Turns out they gave you a session ID instead of an order ID. Doh! This is where resource ID *prefixes* are insanely useful. Think EC2 instance IDs: i-abc123 or EBS volumes: vol-def456. Now when you ask a user for an ID, you'll know immediately if it's the wrong thing entirely. • ☁️ AWS Security Assessment Solution An AWS tool to help you create a point in time assessment of your AWS account using Prowler and Scout as well as optional AWS developed ransomware checks <a href="https://t.co/GQIzBwQdFe" target="_blank">github.com/awslabs/aws-se…</a> • ✅ Kubernetes Security Checklist <a href="https://twitter.com/hashtag/Kubernetes" target="_blank">#Kubernetes</a> documentation page that covers: * Authentication and Authorization * Network security * Pod security * Pod placement * Secrets * Images * Admission controllers <a href="https://t.co/4f2eL4qP3n" target="_blank">kubernetes.io/docs/concepts/…</a> • I've been an advisor to Noq, and I'm thrilled to see <a href="https://twitter.com/ccastrapel" target="_blank">@ccastrapel</a> and <a href="https://twitter.com/krisharms" target="_blank">@krisharms</a> have taken it out of stealth! • Pour yourself a bowl of doritos and mountain dew, grab a spoon, and chow down on this AWS wisdom! • This is a new amazing piece of AWS security tooling! Great work <a href="https://twitter.com/sethsec" target="_blank">@sethsec</a> <a href="https://twitter.com/cvendramini2" target="_blank">@cvendramini2</a> <a href="https://t.co/LiNiSBKOKR" target="_blank">github.com/BishopFox/clou…</a> • lol damn be easy on the French people guys • 🔖 matano An open source security lake platform for AWS. It lets you ingest petabytes of security and log data from various sources, store and query them in an open Apache Iceberg data lake, and create Python detections as code for realtime alerting. <a href="https://t.co/Vo1LxRQNDi" target="_blank">github.com/matanolabs/mat…</a> • Visualizing how S3 deletes 1 billion objects with Athena and Rust • GA! AWS Enterprise Support launches AWS Incident Detection and Response • Unlimited free data storage by (ab)using ECS • Control Tower upgrade Landing Zone from 2.9 to 3.0 -- failures and now disabled • Uber reels from 'security incident' in which cloud systems seemingly hijacked - The Register • stackArmor Achieves AWS Security and AWS Level 1 MSSP Competencies - Business Wire

ASD Logo

19
Monday September, 2022

Sponsor

Who loves managing access to AWS infrastructure across multiple accounts? No one. Its time-consuming complexity creates an unproductive experience for engineers and developers alike.

Teleport makes managing identity-based access to AWS infrastructure dead simple by using a single identity across all your accounts. This allows organizations to tear down access silos while making engineers happy, all while maintaining security and compliance.

Learn more

In a nutshell

Uber was breached by an 18 years old hacker who gained access using Social Engineering, and MFA Push spamming, then got an admin credential found in a PS1 script.

The same kid seems to have breached Rockstar Games and leaked GTA VI footage.

Amazon Elastic Compute Cloud - 11 updated methods
Sep 15
This feature allows customers to create tags for vpc-endpoint-connections and vpc-endpoint-service-permissions.
Amazon SageMaker Service - 4 updated methods
Sep 15
Amazon SageMaker Automatic Model Tuning now supports specifying Hyperband strategy for tuning jobs, which uses a multi-fidelity based tuning strategy to stop underperforming hyperparameter configurations early.
AWS Amplify UI Builder - 8 new 4 updated methods
Sep 14
Amplify Studio UIBuilder is introducing forms functionality. Forms can be configured from Data Store models, JSON, or from scratch. These forms can then be generated in your project and used like any other React components.
Amazon Elastic Compute Cloud - 8 new 10 updated methods
Sep 14
This update introduces API operations to manage and create local gateway route tables, CoIP pools, and VIF group associations.
10 reasons to import a certificate into AWS Certificate Manager (ACM)
Nicholas DoropoulosSep 16
AWS Certificate Manager (ACM) is a service that lets you efficiently provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services and your internal connected resources. The certificates issued by ACM can then be used to secure network communications and establish the identity of websites on …
154 AWS services achieve HITRUST certification
Sonali VaidyaSep 16
The AWS HITRUST Compliance Team is excited to announce that 154 Amazon Web Services (AWS) services are certified for the Health Information Trust Alliance (HITRUST) Common Security Framework (CSF) v9.6 for the 2022 cycle. These 154 AWS services were audited by a third-party assessor and certified under the HITRUST CSF. …
Amazon introduces dynamic intermediate certificate authorities
Adina LozadaSep 14
AWS Certificate Manager (ACM) is a managed service that lets you provision, manage, and deploy public and private Secure Sockets Layer/Transport Layer Security (SSL/TLS) certificates for use with Amazon Web Services (AWS) and your internal connected resources. Starting October 11, 2022, at 9:00 AM Pacific Time, public certificates obtained through …
Use AWS Network Firewall to filter outbound HTTPS traffic from applications hosted on Amazon EKS and collect hostnames provided by SNI
Kirankumar ChandrashekarSep 12
This blog post shows how to set up an Amazon Elastic Kubernetes Service (Amazon EKS) cluster such that the applications hosted on the cluster can have their outbound internet access restricted to a set of hostnames provided by the Server Name Indication (SNI) in the allow list in the AWS …
evidently: 6 new actions, 1 new resource | 4 updated resources, 4 updated actions
Sep 16
6 new actions: CreateSegment (Grants permission to create a segment), DeleteSegment (Grants permission to delete a segment), GetSegment (Grants permission to get segment details), ListSegmentReferences (Grants permission to list resources referencing a segment), ListSegments (Grants permission to list segments), TestSegmentPattern (Grants permission to test a segment pattern); 1 new resource: …
lookoutequipment: 9 new actions, 1 new resource | 1 updated resource, 3 updated actions
Sep 15
9 new actions: CreateLabel (Grants permission to create a label), CreateLabelGroup (Grants permission to create a label group), DeleteLabel (Grants permission to delete a label), DeleteLabelGroup (Grants permission to delete a label group), DescribeLabelGroup (Grants permission to describe a label group), Describelabel (Grants permission to describe a label), ListLabelGroups (Grants …
cloudtrail: 5 new actions, 1 new resource | 3 updated actions, 1 updated resource
Sep 14
5 new actions: CreateServiceLinkedChannel (Grants permission to create a service-linked channel that specifies the settings for delivery of log data to an AWS service), DeleteServiceLinkedChannel (Grants permission to delete a service-linked channel), GetServiceLinkedChannel (Grants permission to list settings for the service-linked channel), ListServiceLinkedChannels (Grants permission to list service-linked channels associated …
kmcquade3
Kinnaird McQuade 💻☁️💥 @kmcquade3

✨Linux tips 🧵

1. Always remove the french language pack:

sudo rm -fr ./*

1.9kSep 16 · 1:22 AM
__steele
Aidan W Steele @__steele

After using AWS for ~14 years, I've internalised a handful of design patterns that I try to apply to my own software. I'm keen to know if it's the same for other folks.

Roughly: tags, IDs (thrice), limits, pagination.

(I'm not going to use the thread emoji)

610Sep 15 · 2:29 AM
__steele
Aidan W Steele @__steele

Turns out they gave you a session ID instead of an order ID. Doh!
This is where resource ID *prefixes* are insanely useful. Think EC2 instance IDs: i-abc123 or EBS volumes: vol-def456.

Now when you ask a user for an ID, you'll know immediately if it's the wrong thing entirely.

6Sep 15 · 2:29 AM
clintgibler
Clint Gibler @clintgibler

☁️ AWS Security Assessment Solution

An AWS tool to help you create a point in time assessment of your AWS account using Prowler and Scout as well as optional AWS developed ransomware checks

github.com/awslabs/aws-se…

37Sep 12 · 11:00 PM
clintgibler
Clint Gibler @clintgibler

✅ Kubernetes Security Checklist

#Kubernetes documentation page that covers:

* Authentication and Authorization
* Network security
* Pod security
* Pod placement
* Secrets
* Images
* Admission controllers

kubernetes.io/docs/concepts/…

32Sep 16 · 11:00 PM
0xdabbad00
Scott Piper @0xdabbad00

I've been an advisor to Noq, and I'm thrilled to see @ccastrapel and @krisharms have taken it out of stealth!

NoqSoftware
Noq Software @NoqSoftware

Noq Noq, who's there?

We are. And we're on a mission to eliminate DevOps pain in IAM while keeping the cloud safe and productive.

Learn more at noq.dev

#iamops #aws #security #devops #iam #cloudsecurity

1Sep 14 · 3:08 AM
0xdabbad00
Scott Piper @0xdabbad00

Pour yourself a bowl of doritos and mountain dew, grab a spoon, and chow down on this AWS wisdom!

__steele
Aidan W Steele @__steele

After using AWS for ~14 years, I've internalised a handful of design patterns that I try to apply to my own software. I'm keen to know if it's the same for other folks.

Roughly: tags, IDs (thrice), limits, pagination.

(I'm not going to use the thread emoji)

4Sep 15 · 4:28 PM
christophetd
Christophe @christophetd

This is a new amazing piece of AWS security tooling! Great work @sethsec @cvendramini2

github.com/BishopFox/clou…

bishopfox
Bishop Fox @bishopfox

Meet CloudFox, a tool that helps you gain situational awareness in unfamiliar #cloud environments. This tool was created for #pentesters + #offsec professionals to find exploitable #attackpaths in cloud infrastructure. @sethsec & @cvendramini2 explain: bfx.social/3qA8Rve

7Sep 13 · 5:00 PM
lancinimarco
Marco Lancini @lancinimarco

🔖 matano

An open source security lake platform for AWS. It lets you ingest petabytes of security and log data from various sources, store and query them in an open Apache Iceberg data lake, and create Python detections as code for realtime alerting.

github.com/matanolabs/mat…

8Sep 14 · 7:30 PM
Unlimited free data storage by (ab)using ECS

Probably not the first person, but I recently discovered an interesting consequence of the way ECS task definitions are implemented that allows indefinitely storing an unlimited amount of arbitrary data for free with no data transfer cost:

  1. You can store arbitrary data in an ECS task definition within the environment …
Control Tower upgrade Landing Zone from 2.9 to 3.0 -- failures and now disabled

UPDATE: Resolved, see final update at end.

To start with, I already have two open cases with support for this :)

I have been planning to upgrade our Control Tower Landing Zone from 2.9 to 3.0 for a while. Opened a case with support to see if there's anything we …