DiscoverBlack Hills Information SecurityOpen Source Exploits in the Cloud's Big Data Services - Cloud TradeCraft
Open Source Exploits in the Cloud's Big Data Services - Cloud TradeCraft

Open Source Exploits in the Cloud's Big Data Services - Cloud TradeCraft

Update: 2019-10-07
Share

Description

4:18 Problem statement and exploitation timeline
8:28 Map reduce and hadoop overview, overview of open source software based on hadoop architecture and their vulnerabilities
14:15 Live demonstration of standing up a stack in EMR, terminology, auto-scaling risks, proper security postures for any new cloud
23:50 Other security resources available to you including EyeWitness, GoWitness, and Webshot
28:43 Continuation of the live demo
33:58 Step by step recreation of the live demonstration with questions answered
43:11 How to combat vulnerabilities in new technologies and staying ahead of the curve, NCC Group's scout
52:16 Q&A and Closing Thoughts

Let's move our ops to the cloud they said. It will be easy, fun, and "secure".

Everything is safe right? The Cloud is certified for every compliance, ever drafted. It must be safe. So what happens when windows get left open on your cloud? How about doors with old rusty locks?

This webcast covers a disclosure first made to AWS support in December of 2018. The conversation was quiet for a while. BHIS re-submitted the disclosure and worked with AWS Security Operations for the next few months to share a finding/vulnerability/exposure, whathaveyou.

Sadly, the nature of the exposure has left many doors open. Those doors lead to virtual private clouds across the globe.

This is one of the scarier webcasts we've been a part of, and for that, we'd like to say we shared everything we could, including a blog write-up that explains in all the gory detail how risky Hue / Hadoop / Spark and the Apache big data clusters can be to an organization. It was originally drafted as "Breaking the Internet" - but this was toned down a bit to "Securing the cloud."

https://www.blackhillsinfosec.com/securing-the-cloud-a-story-of-research-discovery-and-disclosure/

On the webcast, we talk a bit about the nature of open source solutions and the risks they present. We talk a bit about the cloud and the risks it presents. A lot of AWS specific service language is used and hopefully explained in a meaningful way. And, we offer up the Shodan query that identifies the possibly open doors. Oh, we go ahead and demo the nature of the exposure as well (shells).

Also, this webcast serves as a starting point for anyone trying to get started in researching cloud security issues.
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Open Source Exploits in the Cloud's Big Data Services - Cloud TradeCraft

Open Source Exploits in the Cloud's Big Data Services - Cloud TradeCraft

Black Hills Information Security