<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Amazon on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/amazon/</link>
    <description>Recent content in Amazon on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 05 Apr 2013 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/amazon/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Thoughts on Cloud Governance, Part 1</title>
      <link>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</link>
      <pubDate>Fri, 05 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</guid>
      <description>&lt;p&gt;Last week Rapid7 &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets&#34;&gt;posted&lt;/a&gt; an interesting analysis of the Amazon S3 storage system: Apparently roughly one out of six S3 buckets (a bucket is, simply said, a kind of folder) is accessible without any authentication mechanism. Accessing those files, the &lt;a href=&#34;http://www.rapid7.com/&#34;&gt;Rapid7&lt;/a&gt; guys were able to download a &lt;a href=&#34;http://www.google.com/search?q=site%3As3.amazonaws.com+filetype%3Axls+password&amp;amp;btnG=Search&amp;amp;client=opera&amp;amp;oe=utf-8&amp;amp;channel=suggest&amp;amp;gbv=1&#34;&gt;wide range of data&lt;/a&gt;, also comprising confidential information such as source code or employee information, comparable to past research for &lt;a href=&#34;http://blog.rootshell.be/2012/05/19/what-are-you-sharing-with-dropbox/&#34;&gt;other platforms&lt;/a&gt; (see also this presentation I gave on some of the &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;biggest Cloud #Fails&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Key to your Datacenter</title>
      <link>https://insinuator.net/2011/07/the-key-to-your-datacenter/</link>
      <pubDate>Tue, 19 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/the-key-to-your-datacenter/</guid>
      <description>&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;During our ongoing research on the security of cloud service providers and cloud based applications, we performed a regular audit of our &lt;a href=&#34;http://aws.amazon.com&#34; title=&#34;AWS&#34;&gt;AWS&lt;/a&gt; account password. Thinking of &lt;a href=&#34;http://www.wired.com/threatlevel/2009/07/kaminsky-hacked/&#34;&gt;popular incidents&lt;/a&gt; and evergreens in &lt;a href=&#34;%20http://88.84.128.30/~isnochys/wordpress/wp-content/bruteforce.jpg&#34;&gt;attack vectors&lt;/a&gt;, we were wondering which consequences an online bruteforce attack on our AWS password would have. So we decided to perform a bruteforce attack against our own account. Analyzing the login process of AWS, the following requirements for the bruteforce tool to be used could be derived:&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
