® AWS Compromising fun and profit Simon Whittaker Cyber Security Director - Vertical Structure Ltd for
A presentation at Northern Ireland Developer Conference in June 2019 in Belfast, UK by Simon Whittaker
® AWS Compromising fun and profit Simon Whittaker Cyber Security Director - Vertical Structure Ltd for
Simon Whittaker - Lukasz Mrozowski © Vertical Structure Ltd where applicable [email protected]
Prepare, Protect, Persist® • Prepare • We help you and your partners to understand how to identify and resolve potential security issues at the earliest stages with hands on ‘hack yourself first’, threat modelling and GDPR compliance workshops as well as security training for non-technical colleagues. • Protect • Using automated and manual penetration testing techniques, we provide a comprehensive security report for your Web and mobile applications, including API testing, and networks. The report highlights potential issues and their resolutions. • Persist • We ensure that your organisation benefits from continual improvements in security levels through information assurance processes, auditing and certification including ISO27001:2013 and Cyber Essentials. © Vertical Structure Ltd where applicable [email protected]
Bingo https://vsltd.co/bsBingo © Vertical Structure Ltd where applicable [email protected]
Qualifications © Vertical Structure Ltd where applicable [email protected]
Shared Responsibility Model Image from: https://aws.amazon.com/compliance/shared-responsibility-model/ © Vertical Structure Ltd where applicable [email protected]
What do attackers want? © Vertical Structure Ltd where applicable [email protected]
Working fast • IAM is confusing • Use principle of least privilege • Never commit credentials https://technodrone.blogspot.com/2019/03/the-anatomy-ofaws-key-leak-to-public.html © Vertical Structure Ltd where applicable [email protected]
IAM © Vertical Structure Ltd where applicable [email protected]
Let’s have a play All exploits are being performed in a safe environment © Vertical Structure Ltd where applicable [email protected]
Example 1 – EC2 escalation © Vertical Structure Ltd where applicable [email protected]
Bob’s permissions © Vertical Structure Ltd where applicable [email protected]
The process © Vertical Structure Ltd where applicable [email protected]
Example 2 - Escalation to IAM Administrator © Vertical Structure Ltd where applicable [email protected]
Joe’s permissions © Vertical Structure Ltd where applicable [email protected]
The process © Vertical Structure Ltd where applicable [email protected]
Consequences © Vertical Structure Ltd where applicable [email protected]
Fun and Profit © Vertical Structure Ltd where applicable [email protected]
Try for yourself • Cloudgoat https://github.com/RhinoSec urityLabs/cloudgoat © Vertical Structure Ltd where applicable [email protected]
Protection Measures • Ask questions • Some great advice from UK NCSC • Secure users • Reduce privileges • Implement tools to help you © Vertical Structure Ltd where applicable [email protected]
Bingo results © Vertical Structure Ltd where applicable [email protected]
Questions? [email protected] @szlwzl https://vsltd.co/NIDevConf19