
DEF CON 32 - Secrets & Shadows: Leveraging Big Data for Vulnerability Discovery - Bill Demirkapi
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 42:24
The main goal of this talk is to demonstrate how vulnerabilities like dangling cloud resources and leaked secrets can be discovered at scale using unconventional data sources and a shift from target-specific to data-driven approaches. By leveraging passive DNS replication and virus scanning platforms, the speaker reveals a more effective, scalable method for identifying these issues beyond traditional, narrow-target techniques.
• Dangling DNS records can be found by enumerating cloud IP pools and cross-referencing with passive DNS data, revealing over 2 million unique IPs across AWS and Google Cloud 2:58.
• A scalable secret scanning approach uses virus scanning platforms to search for secret patterns (e.g., AWS keys, GitHub tokens) instead of targeting individual repositories, discovering over 15,000 validated secrets including 2,400 AWS keys and 600 Stripe accounts 19:00.
• Cloud providers implemented deterrents (e.g., IP pools, billing limits) to block enumeration, but these were bypassed using techniques like ephemeral EC2 restarts and Google Workspace account creation, enabling large-scale discovery 25:01.
• AWS access keys posted publicly on GitHub are not automatically revoked, with some keys still active and accessible—highlighting a critical gap in provider response and security defaults 40:56.
This work underscores the need for industry-wide solutions to track cloud resource ownership and enforce secure defaults, especially to eliminate the "path of least resistance" in hardcoding secrets or leaving dangling DNS records.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
killing me dude all right everyone thank you so much for coming out to this talk it's called secrets and shadows leveraging big data for vulnerability Discovery at scale I'm so excited to be here for another year at another Devcon and I really do have something in store for you today let's get right into it so just a disclaimer everything we're going to tell talk about today was done completely independent of my employer outside of work with my own money my own resources um if you want to talk about this work outside of this presentation just please refer to me as an independent security researcher it helps me be able to do work just like this so my name is Bill DiMera and I'm a security researcher who with a diverse background in low-level software security and also Cloud security uh coul…