DEF CON 32 - OH MY DC  Abusing OIDC all the way to your cloud - Aviad Hahami

DEF CON 32 - OH MY DC Abusing OIDC all the way to your cloud - Aviad Hahami

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 37:37

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video explores how OIDC (OpenID Connect) misconfigurations in CI/CD pipelines can lead to unauthorized access to cloud resources, emphasizing the risks of lax policies and improper claim assertions. 0:30

Key Takeaways:
• OIDC in CI/CD uses identity federation to authenticate machines, but the CI provider acts as both the CI and identity provider, creating trust dependencies 2:51.
• ID tokens contain claims like sub, repo, and workflow, and their values can be exploited if policies use wildcards or unsafe patterns 9:02.
• "No config" or lax policies allow any ID token to pass, enabling attackers to impersonate identities via copy-paste workflows 13:55.
• Custom claim formats, especially in the sub field, are vulnerable to order-based attacks—flipping claim order can bypass authorization 22:56.
• Pipeline abuse via pull request forks can trigger vulnerable CI executions, leading to access to restricted cloud resources 25:33.
• Vendor misconfigurations, such as Circle CI granting OIDC tokens on any fork pull request, enable broad access to cloud accounts without proper opt-in 32:00.

Attackers can exploit weak policies, unsafe claims, or vendor flaws to gain unauthorized access. Organizations should harden pipelines, avoid wildcards, validate claim origins, and ensure proper identity assertions. 37:12

Sources:

  • 0:30 Overview of OIDC in CI/CD and its authentication flow.
  • 2:51 Explanation of OIDC

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

yay yay yay what's up good to go okay so uh hi everybody today's talk is called om IDC where we're going to learn and see how we can we abuse oidc setups in the context of CI um this is extremely exciting for me that's my first time speaking in in the con so thank you very much for showing up and thank thank you very much for having me that was the first voice breakdown so it's fine okay uh by the way fan and John are here thank you for the buildup I hope I'll satisfy that so I'll present myself my name is avat kakami this is my Twitter Handler I do security research at pal Alto um I do CI domain mainly I welcome you to check my latest publication uh this is aure CLI um information leage with the 8.6 score somehow uh but it probably affected all your AGG uh usage is I also do bug Bounty I …