SRE Weekly Issue #353 • Amazon EMR - 1 new methods • AWS Secrets Manager - 2 updated methods • Amazon ElastiCache - 15 updated methods • AWS Network Firewall - 3 updated methods • iotroborunner: 1 removed resource, 1 removed condition • autoscaling: 1 removed condition • connect: 1 new action • Blog | Cloud Cred Harvesting Campaign - Grinch Edition • Security vendor: "You should absolutely be defining your infrastructure in code; it's a security best practice." Also security vendor: "So to configure our product, just log in to our UI and follow these 85 point-and-click steps." • New year, new <a href="https://twitter.com/hashtag/AWS" target="_blank">#AWS</a> project! ⌨️☁️ I loved the KMS external key stores announcement so I made a mock external key manager using APIGW, Lambda and DDB to learn how it works and mess with keying material. You can deploy this yourself by installing from <a href="https://t.co/OmaCZ8wkjN" target="_blank">github.com/iann0036/toyxks</a> • I used to think this too. It's uncouth to talk about money, but having a software engineering degree opens up life-changing opportunities for Australians willing to work in the USA. It can literally make you more than ONE MILLION DOLLARS better off in four years. • You have got to be shitting me. Are these abbreviations both really used in the infosec industry? • Last week, I reported a public bucket at a French bank, filled with about 16GB of data, with nothing noteworthy except static assets. They gave me a credit of $10 for the report. Security for living, I guess :) • 7 years in a row (after fixing it for just two years) ... Google continues to be an absolute mess of "organizing the world's information" with lyrics. This year they credit Rod Stewart for Auld Lang Syne. Previous years include Kenny G and Billy Joel. • if you're in the seattle area, my friend colleen (wedding florist! flower farmer! event planner!) is doing a monthly bouquet club this year from april to october 💐 do every month, pick a few of the months. get pretty, locally-grown flowers. <a href="https://t.co/E6G7mEcFde" target="_blank">diademflowers.com/flower-shop/p/…</a> • It’s been an amazing year for Datadog Security Labs! We’ve released a number of open source tools, shared the results of our research projects. Be sure to subscribe to our RSS feed, we have more cloud vulnerabilities to be released soon :) <a href="https://t.co/QyaaO5BRuq" target="_blank">securitylabs.datadoghq.com/articles/secur…</a> • I'm stoked to be speaking at <a href="https://twitter.com/wiz_io" target="_blank">@wiz_io</a>'s CloudSec 360! Hope to see you there 👇 • Today just isn't the same without a Chaos Communication Congress. So many great talks and such a perfect week for soaking in the mind-blowing breaks and exploits. Hoping for its return! <a href="https://t.co/ibP2NYbKDM" target="_blank">twitter.com/i/web/status/1…</a> • AWS CIRT announces the release of five publicly available workshops • Whats the point of IPv6 native subsets if they don't support auto-scaling target groups? • Is fargate the right choice for my apps? • Redirecting to either S3 or API Gateway depending on the endpoint (more details in comment) • 2022 Review: Cloud Tech Chaos - Forbes • AWS, Microsoft, Google Doubled Down on Cloud Security in 2022 - SDxCentral • AWS IP Ranges update for 2022-12-16 08:13:06 • AWS IP Ranges update for 2022-12-16 14:03:09

ASD Logo

2
Monday January, 2023

In a nutshell

Happy New Year, fellow AWS security professionals! As we kick off a new year, let's resolve to stay vigilant and keep our cloud infrastructure secure. From implementing proper identity and access management to regularly reviewing and updating security policies, let's make this year the safest one yet for our organization. Here's to a happy and secure new year!

📢 MAMIP (Monitor AWS Managed IAM Policies)

Policies changed since last week:

Weekly diff


🪖 Army of AWS Bots: MAMIP / MASE / MGDA / MIRA

Amazon EMR - 1 new methods
Dec 29
Added GetClusterSessionCredentials API to allow Amazon SageMaker Studio to connect to EMR on EC2 clusters with runtime roles and AWS Lake Formation-based access control for Apache Spark, Apache Hive, and Presto queries.
AWS Secrets Manager - 2 updated methods
Dec 29
Added owning service filter, include planned deletion flag, and next rotation date response parameter in ListSecrets.
Amazon ElastiCache - 15 updated methods
Dec 28
This release allows you to modify the encryption in transit setting, for existing Redis clusters. You can now change the TLS configuration of your Redis clusters without the need to re-build or re-provision the clusters or impact application availability.
AWS Network Firewall - 3 updated methods
Dec 28
AWS Network Firewall now provides status messages for firewalls to help you troubleshoot when your endpoint fails.
iotroborunner: 1 removed resource, 1 removed condition
Dec 31
1 removed resource: TaggingResource; 1 removed condition: iotroborunner:TaggingResourceTagKey (Filters access by the metadata tag name)
autoscaling: 1 removed condition
Dec 31
1 removed condition: autoscaling:TrafficSourceIdentifiers (Filters access based on the identifiers of the traffic sources)
connect: 1 new action
Dec 31
1 new action: UpdateParticipantRoleConfig (Grants permission to update participant role configurations associated with a contact)
matthewdfuller
Matt Fuller @matthewdfuller

Security vendor: "You should absolutely be defining your infrastructure in code; it's a security best practice."

Also security vendor: "So to configure our product, just log in to our UI and follow these 85 point-and-click steps."

3Dec 26 · 5:04 PM
iann0036
Ian Mckay @iann0036

New year, new #AWS project! ⌨️☁️

I loved the KMS external key stores announcement so I made a mock external key manager using APIGW, Lambda and DDB to learn how it works and mess with keying material.

You can deploy this yourself by installing from github.com/iann0036/toyxks

2Jan 01 · 5:35 AM
__steele
Aidan W Steele @__steele

I used to think this too. It's uncouth to talk about money, but having a software engineering degree opens up life-changing opportunities for Australians willing to work in the USA. It can literally make you more than ONE MILLION DOLLARS better off in four years.

jarredsumner
Jarred Sumner @jarredsumner

college doesn’t matter

4Dec 29 · 8:43 AM
__steele
Aidan W Steele @__steele

You have got to be shitting me. Are these abbreviations both really used in the infosec industry?

2Dec 28 · 11:45 PM
zoph
Victor Grenu @zoph

Last week, I reported a public bucket at a French bank, filled with about 16GB of data, with nothing noteworthy except static assets. They gave me a credit of $10 for the report. Security for living, I guess :)

3Dec 27 · 9:46 PM
colmmacc
Colm MacCárthaigh @colmmacc

7 years in a row (after fixing it for just two years) ... Google continues to be an absolute mess of "organizing the world's information" with lyrics. This year they credit Rod Stewart for Auld Lang Syne. Previous years include Kenny G and Billy Joel.

colmmacc
Colm MacCárthaigh @colmmacc

6 years now and the Google lyrics team continue to get the basics woefully wrong. They're still falsely attributing long out of copyright Robert Byrne's "Auld Lang Syne" to Dougie MacClean, but now also Theodore Shapiro. I've now submitted 5 corrections, to no avail.

0Dec 28 · 4:40 PM
abbyfuller
Abby Fuller @abbyfuller

if you're in the seattle area, my friend colleen (wedding florist! flower farmer! event planner!) is doing a monthly bouquet club this year from april to october 💐

do every month, pick a few of the months. get pretty, locally-grown flowers.

diademflowers.com/flower-shop/p/…

3Dec 26 · 9:24 PM
Frichette_n
Nick Frichette - @frichetten@fosstodon.org @Frichette_n

It’s been an amazing year for Datadog Security Labs! We’ve released a number of open source tools, shared the results of our research projects. Be sure to subscribe to our RSS feed, we have more cloud vulnerabilities to be released soon :)

securitylabs.datadoghq.com/articles/secur…

0Dec 30 · 4:47 PM
clintgibler
Clint Gibler @clintgibler

I'm stoked to be speaking at @wiz_io's CloudSec 360!

Hope to see you there 👇

wiz_io
Wiz @wiz_io

Check this out — tldrsec.com creator @clintgibler has been added to the CloudSec 360 lineup!

Join to learn how to identify issues before production, build automation into your processes and scale your security into the future 🚀

1Dec 29 · 7:38 PM
colmmacc
Colm MacCárthaigh @colmmacc

Today just isn't the same without a Chaos Communication Congress. So many great talks and such a perfect week for soaking in the mind-blowing breaks and exploits. Hoping for its return! twitter.com/i/web/status/1…

1Dec 27 · 5:14 PM
Whats the point of IPv6 native subsets if they don't support auto-scaling target groups?

Anyone else know how to get around target groups not supporting IPv6 ec2 instance targets? They only support hardcoded IPv6 addresses, which doesn't really work with EC2 auto scaling and load balancing.

https://github.com/aws/containers-roadmap/issues/1653

https://docs.aws.amazon.com/elasticloadbalancing/latest/network/load-balancer-target-groups.html#target-group-ip-address-type

" IPv6 target groups only support IP type targets."

Kind of posting this for visibility too. …

Is fargate the right choice for my apps?

With my company we are developing several web applications.
We are using fargate clusters to run our applications backends (usually laravel apps).
We are using a load balancer to route the traffic to the different containers and the frontends are served by cloudfront.
My question is: are fargate clusters the …