5 ms·
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years
by kmcquade 6y ago
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along.
>...and it's not even a hacking tool!
It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it on a pentest :)
- sodality2 6y agoWell, you know the saying about eggs and omelettes. I wish you luck with getting AWS to listen to you!
- kmcquade 6y agoThanks :)
- denismurphy 6y agoyou're an evil genius
- Operyl 6y agoI'm impressed you were able to get your employer (Salesforce) to actually let you publish this under their organization. Kudos to that.
- mushufasa 6y agoSalesforce also runs Heroku, which is one of the biggest AWS wrappers around. I'm really glad they're active in security auditing here, it's a real value add to customers of Heroku / Salesforce services to see evidence of their work to analyze security.
- kerng 6y agoYes, surprised also, given past stories around Defcon. I think it's great to have audit tools like this. It makes people realize how vulnerable their accounts are. Does a similar tool exist for Salesforce and Heroku?
- jasperran 6y agoNot sure what the shock is with seeing security tools like this released, the vast majority of security tools are open source, how is this different to what we have been seeing the past 30 year? Not to mention companies such as Google, Netflix and Mozilla all release security tools just like this.
- Mandatum 6y agoI guess they didn't.
- Operyl 6y agoThat’s what I was expecting to happen, unfortunately.
- stjohnswarts 6y agoSo did you just put this out there or did you give AWS Security peeps a week or two notice?
- jasperran 6y agoThis isn't exploiting a vulnerability. This requires authentication and uses AWS features. Why would they need to alert AWS?
- Blahah 6y agoCan you share the code somewhere else? It's been taken down from github
- cambalache 6y agohttps://files.pythonhosted.org/packages/0c/f0/9eced7d6c57483c49db1a5bdbb4061e5f8346a3701bef9354e98b7f3f84e/endgame-0.2.0.tar.gz https://files.pythonhosted.org/packages/0c/f0/9eced7d6c57483...
- jeffmcjunkin 6y agoBugs get patched. Features are protected, and sometimes simultaneously abused. Thank you!
- PeterCorless 6y ago404. Did they pull the repo or make it private? https://github.com/salesforce/endgame https://github.com/salesforce/endgame