
DEF CON 32 - AWS CloudQuarry: Digging for secrets in public AMIs - Eduard Agavriloae, Matei Josephs
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 39:34
Researchers discovered that companies were exposing sensitive secrets through publicly accessible AWS Machine Images (AMIs) 0:00-0:05, presenting a significant cloud security risk.
Key Takeaways:
• The team developed an efficient method to scan public AMIs by detaching and reattaching volumes within AWS 9:05-9:10
• They found 120 valid AWS access keys, including 20 root keys, giving access to over 100 companies including Fortune 500 companies 19:01-19:04
• Despite responsible disclosure attempts, less than 10% of companies responded, showing poor security response practices 28:56-29:00
• AWS security team successfully invalidated over 60 exposed access keys after being contacted 30:07-30:10
The research demonstrates that cloud security hygiene remains insufficient, with developers mistakenly believing private resources in public AMIs remain secure 35:31-35:40.
Sources:
- 0:00-0:05 Introduction about secrets in public cloud resources
- 9:05-9:10 Explanation of the "secret searcher instance" method
- 19:01-19:04 Discovery of 120 valid AWS credentials
- 28:56-29:00 Challenges with responsible disclosure responses
- 30:07-30:10 AWS security team invalidating access keys
- 35:31-35:40 Conclusion about insufficient cloud security practices
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
hello Devcon so I'm very happy to be here this has been a dream of mine for many many years and uh thanks for being part of it this research is about a cool story about um secrets in public Cloud resources and um you know uh who thinks we will never run out of customers Public public sharing secrets in public Cloud resources yeah I think I think we will never run out of that and um my name is Edward aav I was a senior penetration tester at KPMG Romania while I've done uh This research uh huge shout out to them for supporting the the the research and trusting this idea uh I was also a contractor at sin cubes uh I I mean I still am and I'm doing offensive Cloud projects there I also worked one Mount at Crow strike but I resigned on Friday so [Applause] so I'm open for New Opportunities and u…