Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kmcquade
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
1.
▲
Pwning AWS Bedrock AgentCore's AI Code Interpreter
(beyondtrust.com)
8 points
by
kmcquade
7mo ago
|
0 comments
2.
▲
by
kmcquade
1y ago
These guys do an insane amount of engineering to speed up builds and everyone follows. Love their blogs. Zero chance I'd sign up for their competitors knowing how good the product is and that everyone else follows them. I don't kn
3.
▲
by
kmcquade
3y ago
Depot is freaking awesome. Sped up two of our Docker image builds from 11 minutes to 1-1.5 minutes and the drop-in Docker build replacement in GitHub Actions was super easy. Can't imagine our CI/CD system without it.
4.
▲
by
kmcquade
4y ago
Love using Depot. The speed improvements are insane
5.
▲
Metabadger: Prevent SSRF Attacks on AWS EC2 via Automatic Upgrades to IMDSv2
(github.com)
1 points
by
kmcquade
5y ago
|
0 comments
6.
▲
Show HN: Cloud Guardrails – Rapidly apply 100s of security controls in Azure
(github.com)
3 points
by
kmcquade
5y ago
|
0 comments
7.
▲
by
kmcquade
6y ago
> the tool can discover incorrect configurations that would allow someone who extracted the key to change permissions of the bucket. Nit: The tool can discover and abuse excessive permissions.
8.
▲
by
kmcquade
6y ago
Yes, you'd have to leverage compromised credentials. That could be obtained via SSRF, RCE on a privileged box, leakage of user access keys, or other means. In the context of a penetration test, it's more of a post-exploitation too
9.
▲
by
kmcquade
6y ago
Aw, thank you. I really appreciate that.
10.
▲
by
kmcquade
6y ago
Great feedback! I will update the docs accordingly.
11.
▲
by
kmcquade
6y ago
Not sure. I did uncover a ridiculously destructive approach to abusing Azure Service Principals in CI/CD pipelines that deploy infrastructure in Azure (Confused Deputy problem): https://kmcquade.com/2020/11/nu
12.
▲
by
kmcquade
6y ago
Dry run as default is a good idea. I'll open a GitHub issue for that. FWIW, if you run `endgame smash` with `--service all`, then it spits out a huge "WARNING" in ASCII art with an explanation and a confirmation prompt. But I
13.
▲
by
kmcquade
6y ago
Thanks :)
14.
▲
by
kmcquade
6y ago
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. &g
15.
▲
Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
(github.com)
368 points
by
kmcquade
6y ago
|
93 comments
16.
▲
by
kmcquade
6y ago
Did you open source it? If not, you definitely should.
17.
▲
by
kmcquade
6y ago
I wish.
18.
▲
by
kmcquade
6y ago
You are so right on the SELinux comparison. Of course, in this case, there are way more developers that are required to write them. Reiterating what was mentioned in the thread - the best way to avoid this wildcard situation and make it eas
19.
▲
by
kmcquade
6y ago
You just need a single IAM action - iam:GetAccountAuthorizationDetails ( https://docs.aws.amazon.com/IAM/latest/APIReference/API_GetA... ). I’ll definitely add that to the README. Thanks
20.
▲
by
kmcquade
6y ago
PMapper is definitely a great tool. It’s best used in Pentests for validating some privilege escalation paths. It has the benefit of analyzing IAM trust policies, resource based policies, viewing escalation paths in a graph based approach.
21.
▲
by
kmcquade
6y ago
Thanks! I’m glad you like it. Let me know if you have any feedback - here, in the Gitter channel (link in the Readme), or on Twitter (kmcquade3)
22.
▲
Show HN: Cloudsplaining, an AWS IAM Security Assessment Tool
(github.com)
6 points
by
kmcquade
6y ago
|
6 comments
23.
▲
Automating Least Privilege in AWS IAM with Policy Sentry
(engineering.salesforce.com)
2 points
by
kmcquade
7y ago
|
0 comments
24.
▲
by
kmcquade
7y ago
With this. https://github.com/salesforce/policy_sentry (Disclaimer: I am the author) Not one step exactly, but it is by far the easiest way to write least privilege IAM policies. Otherwise, it becomes impossible to ens
25.
▲
by
kmcquade
7y ago
Pretty awesome that it’s open source. For large companies there are some proprietary solutions for this. Example: https://www.trendkite.com/ Disclaimer: family member works there so that’s the reason I’m aware that this nic
26.
▲
by
kmcquade
7y ago
> "I'm pretty excited, I've never won a single thing in my life before. And to do it in service of taking down evil patent trolls? This is one of the best days of my life, no joke. I submitted because software patents are
27.
▲
by
kmcquade
7y ago
My email is also in my profile :)
28.
▲
by
kmcquade
7y ago
Aardvark and Repokid revoke privileges based on AWS Access Advisor, which tells you when certain services have not been used within X amount of days/months. But it only does this for services, not for actions. So the resulting API call
29.
▲
by
kmcquade
7y ago
It does, but some disclaimers: 1. The generated policies have Resources set to all, not to a specific resource ARN 2. It downloads all of the CloudTrail logs. This takes a while. Cloudtracker ( https://github.com/duo-labs
30.
▲
by
kmcquade
7y ago
I hear you. Generating IAM policies based on CloudTrail records would be amazing. See my comment here: https://news.ycombinator.com/item?id=21262954#21264166 I hope to build this into our roadmap.
More ›