3 ms·
About to take a whack at reading your paper, but in plain programmer speak, can you explain a few ways this might be exploited in the wild?
by idealmedtech 4y ago
About to take a whack at reading your paper, but in plain programmer speak, can you explain a few ways this might be exploited in the wild?
- ericpauley 4y agoBiggest finding is that adversaries can easily allocate many IPs on public clouds. From this, automated traffic analysis can find what we call latent configurations (e.g., subdomain takeover) and exploit these. For instance you could allocate cloud IPs to collect SNS messages with PII to phish people, or receive passwords or data intended for other sites. More high-level description here: https://pauley.me/post/2022/cloud-squatting/ https://pauley.me/post/2022/cloud-squatting/
- idealmedtech 4y agoThat's so interesting! Giving me an idea for a side project that I'm sure has been done many times before :)