<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/cloud/</link>
    <description>Recent content in Cloud on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 02 Aug 2023 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/cloud/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Select * from OpenStack - A Steampipe Plugin for OpenStack</title>
      <link>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</link>
      <pubDate>Wed, 02 Aug 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/08/select-from-openstack-a-steampipe-plugin-for-openstack/</guid>
      <description>&lt;p&gt;Although, more and more companies start to move their IT-Infrastructure from&#xA;on-premise to public cloud solutions like Amazon Web Services (AWS) and&#xA;Microsoft Azure, public cloud providers are not an option for every&#xA;organization. This is where private cloud platforms come into play as they give&#xA;organizations direct control over their information, can be more energy&#xA;efficient than other on-premise hosting solutions, and offer companies the&#xA;possibility to manage their data centers efficiently.&#xA;&lt;a href=&#34;https://www.openstack.org/&#34;&gt;OpenStack&lt;/a&gt; is a widely deployed, open-source&#xA;private cloud platform many companies and universities use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>#TR18 Defense &amp; Management Summaries</title>
      <link>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</link>
      <pubDate>Fri, 23 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/%23tr18-defense-management-summaries/</guid>
      <description>&lt;p&gt;This blogpost contains summaries of talks from this year’s &lt;a href=&#34;https://www.troopers.de/troopers18/&#34;&gt;TROOPERS18&lt;/a&gt; Defense &amp;amp; Management Track.&lt;/p&gt;&#xA;&lt;h1 id=&#34;all-your-cloud-are-belong-to-us&#34;&gt;All Your Cloud Are Belong to Us&lt;/h1&gt;&#xA;&lt;p&gt;The talk “All Your Cloud Belong Are Belong to Us” was held by &lt;a href=&#34;https://twitter.com/dk_effect&#34;&gt;Nate Warfield&lt;/a&gt;, who is a Senior Security Program Manager for the Microsoft Security Response Center (MSRC).&lt;br&gt;&#xA;Before Microsoft he worked as a network engineer about 18 years and 10 of this for a large amount of cell phone companies.&lt;br&gt;&#xA;Nate gives an overview about the state of the cloud solution provided by Microsoft, Azure, and how he hunts vulnerabilities in this environment.&lt;br&gt;&#xA;Finally he concludes that the giving up your infrastructure to the cloud doesn’t mean that you give up your responsibility.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Auditing AWS Environments</title>
      <link>https://insinuator.net/2018/03/auditing-aws-environments/</link>
      <pubDate>Wed, 07 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/auditing-aws-environments/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Related to our new TROOPERS workshop &lt;a href=&#34;https://troopers.de/troopers18/trainings/jfc3gg/&#34;&gt;“Jump-Starting Public Cloud Security”&lt;/a&gt;, this post is going to describe some relevant components which need to be taken care of when constructing and auditing an Amazon Web Services (AWS) cloud environment. Those include amongst others the general AWS account structure, Identity and Access Management (IAM), Auditing and Logging (CloudTrail and CloudWatch), Virtual Private Cloud (VPC) networks, as well as S3 buckets.&lt;/p&gt;&#xA;&lt;p&gt;The AWS IAM service is responsible for identity and access management (surprise!). This includes managing user accounts, defining password policies, and – most importantly – creating, defining, and assigning groups and roles.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSA Summit CEE and BSides Ljubljana 2017</title>
      <link>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</link>
      <pubDate>Fri, 17 Mar 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/03/csa-summit-cee-and-bsides-ljubljana-2017/</guid>
      <description>&lt;p&gt;At the end of last week I had the pleasure to visit the &lt;a href=&#34;https://csa-cee-summit.eu/&#34;&gt;CSA Summit CEE&lt;/a&gt; and the &lt;a href=&#34;https://bsidesljubljana.si/&#34;&gt;Bsides Event in Ljubljana&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;At CSA, I was talking about hypervisors, breakouts and an overview of security measures to protect the host. (&lt;a href=&#34;https://csa-cee-summit.eu/florian-magin/&#34;&gt;Slides&lt;/a&gt;)&lt;br&gt;&#xA;This ranged from the basic features some hypervisors provide out of the box to advanced features like SELinux, device domain models and XSM-FLASK.&lt;/p&gt;&#xA;&lt;p&gt;Most of the other talks were more targeted towards management level employees, but even as a fairly technical person I found Mike Bursell’s &lt;a href=&#34;https://csa-cee-summit.eu/mike-bursell/&#34;&gt;talk&lt;/a&gt;  highly interesting. After my talk about securing the host system from a malicious guest, he dealt with the inverse: Technologies to protect a guest from a malicious or compromised host.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SIGS DC Day</title>
      <link>https://insinuator.net/2016/09/sigs-dc-day/</link>
      <pubDate>Fri, 16 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/sigs-dc-day/</guid>
      <description>&lt;p&gt;Today I had to give the pleasure to give a keynote at the &lt;a href=&#34;http://digs.ch/dc-day/&#34;&gt;SIGS DC Day&lt;/a&gt; on the need to evaluate Cloud Service Providers in a way that looks behind (or at least tries to) security whitepapers and certification reports. The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_TrustEvaluationCloudProvider_mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I also particularly enjoyed the following two talks:&lt;/p&gt;&#xA;&lt;p&gt;Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud migration. Even though he only briefly touched the topic, I enjoyed his description of their firewalling model: Seeing that centralized firewall operation (or more precisely, rule design and approval) is limited/challenged by the understanding of the application, they transferred control over firewall rule sets (beyond a basic set of infrastructure/ground rules) to the application teams (using of features like OpenStack’s security groups, where he also talked about limitations of those). They compensated the loss of “centralized enforcement by a security group” with rule reviews — an approach that will become way more relevant (and necessary) in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A Trip to Hannover Messe</title>
      <link>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</link>
      <pubDate>Wed, 27 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/a-trip-to-hannover-messe/</guid>
      <description>&lt;p&gt;Once every few years I decide to head to Hannover and attend &lt;a href=&#34;http://www.hannovermesse.de/&#34;&gt;Hannover Messe&lt;/a&gt;, probably the largest industrial trade fair in Germany and apparently on of the most important in the world. As this year’s main topic was “Industrie 4.0” I simply could not resist to go out on a hunt for new and interesting (secure) smart connected magic! And trust me, I was not disappointed – here’s a few of my impressions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud Security &amp; Trust</title>
      <link>https://insinuator.net/2016/03/cloud-security-trust/</link>
      <pubDate>Thu, 10 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/cloud-security-trust/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I gave a presentation on Cloud Security, Compliance &amp;amp; Trust the other day. The basic message was to look beyond the Cloud buzzword and see the actual technologies which are used, understand which security principles still apply and which need to be re-thought, giving a rough direction about regulatory compliance in Cloud environments (which of course is non-binding, as I’m not a lawyer), and the importance of trust evaluations (especially) when it comes to Cloud services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Cloud Services Router 1000V and the Virtual Matryoshka</title>
      <link>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</link>
      <pubDate>Mon, 28 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/cisco-cloud-services-router-1000v-and-the-virtual-matryoshka/</guid>
      <description>&lt;p&gt;Recently we started playing around with Cisco’s virtual router, the CSR 1000V, while doing some protocol analysis. We found Cisco offering an BIN file for download (alternatively there is an ISO file which contains a GRUB boot loader and the BIN file, or an OVA file which contains a virtual machine description and the ISO file) and file(1) identifies it as DOS executable:&lt;/p&gt;&#xA;&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;$ file csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin &#xA;    csr1000v-universalk9.03.12.00.S.154-2.S-std.SPA.bin: DOS executable (COM)&lt;/code&gt;&lt;/pre&gt;&#xA;&lt;p&gt;We didn’t manage to get the file running, neither in a (Free-)DOS environment, nor in a wine virtual DOS environment, except using the boot loader from the ISO file. So we became curious as for the structure and ingredients of the file.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IPv6 Requirements for Cloud Service Providers</title>
      <link>https://insinuator.net/2014/07/ipv6-requirements-for-cloud-service-providers/</link>
      <pubDate>Tue, 08 Jul 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/07/ipv6-requirements-for-cloud-service-providers/</guid>
      <description>&lt;p&gt;Some weeks ago, at RIPE 68 in Warsaw, &lt;a href=&#34;http://www.steffann.nl/site/&#34;&gt;Sander Steffann&lt;/a&gt; gave a &lt;a href=&#34;https://ripe68.ripe.net/presentations/340-RIPE-554bis.pdf&#34;&gt;presentation about revising RIPE 554&lt;/a&gt; which, in his own words, “is a template guideline for procurement of stuff that should do IPv6” (&lt;a href=&#34;https://ripe68.ripe.net/archives/steno/38/&#34;&gt;here’s&lt;/a&gt; the steganography transcript of the IPv6 working group session). Some of you will probably know &lt;a href=&#34;https://www.ripe.net/ripe/docs/ripe-554&#34;&gt;RIPE 554&lt;/a&gt; as a quite helpful document for identifying reasonable real-world requirements for IPv6 capable network devices (in particular at times when vendors quite willingly put an “IPv6 ready” sticker on all their gear…).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Exploiting Hyper-V: How We Discovered MS13-092</title>
      <link>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</link>
      <pubDate>Tue, 14 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/exploiting-hyper-v-how-we-discovered-ms13-092/</guid>
      <description>&lt;p&gt;During a recent research project we performed an in-depth security assessment of Microsoft’s virtualization technologies, including Hyper-V and Azure. While we already had experience in discovering security vulnerabilities in other virtual environments (e.g. &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;), this was our first research project on the Microsoft virtualization stack and we took care to use a &lt;a href=&#34;http://www.insinuator.net/2013/05/analysis-of-hypervisor-breakouts/&#34;&gt;structured evaluation strategy&lt;/a&gt; to cover all potential attack vectors.&lt;br&gt;&#xA;Part of our research concentrated on the Hyper-V hypervisor itself and we discovered a critical vulnerability which can be exploited by an unprivileged virtual machine to crash the hypervisor and potentially compromise other virtual machines on the same physical host. This bug was recently patched, see &lt;a href=&#34;https://technet.microsoft.com/en-us/security/bulletin/ms13-092&#34;&gt;MS13-092&lt;/a&gt; and our &lt;a href=&#34;http://www.insinuator.net/2014/01/state-of-virtualization-security-14/&#34;&gt;corresponding post&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>State of Virtualization Security ‘14</title>
      <link>https://insinuator.net/2014/01/state-of-virtualization-security-14/</link>
      <pubDate>Sun, 05 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/state-of-virtualization-security-14/</guid>
      <description>&lt;p&gt;First of all, I hope you all had a good start to 2014. Having some time off “between the years” (which is a German saying for the time between Christmas and NYE), I caught up on several virtualization security topics.&lt;/p&gt;&#xA;&lt;p&gt;While virtualization is widely accepted as a sufficiently secure technology in many areas of IT operations (also for sensitive applications or exposed systems, like &lt;a href=&#34;http://www.insinuator.net/2009/12/some-reflections-on-virtualization-security-part-1/&#34;&gt;DMZs&lt;/a&gt;) by 2014, there are several recent vulnerabilities and incidents that are worth mentioning.&lt;/p&gt;</description>
    </item>
    <item>
      <title>3D-Printers in the Cloud</title>
      <link>https://insinuator.net/2013/11/3d-printers-in-the-cloud/</link>
      <pubDate>Wed, 27 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/3d-printers-in-the-cloud/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Dear readers,&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;with the rise of low-cost 3D-printers in the homes of thousands [1] of enthusiastic tinkerers the word spreads about these magical machines which can produce any mechanical, artsy, useful or useless parts you might come up with. Standing in living rooms worldwide, they don’t seem like a big threat [2] to anybody. But what happens if you connect them to the Internet?&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;http://www.insinuator.net/wp-content/uploads/2013/11/TROOPERS_3Dprinters.jpg&#34; alt=&#34;3D-Printers at the TROOPERS12 &amp;amp; TROOPERS13 IT-Security Conference.&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of Hypervisor Breakouts</title>
      <link>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</link>
      <pubDate>Mon, 20 May 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/05/analysis-of-hypervisor-breakouts/</guid>
      <description>&lt;p&gt;In the course of a current virtualization research project, I was reviewing a lot of documentation on hypervisor security. While “hypervisor security” is a very wide field, hypervisor breakouts are usually one of the most (intensely) discussed topics. I don’t want to go down the road of rating the risk of hypervisor breakouts and giving appropriate recommendations (even though we do this on a regular base which, surprisingly often, leads to almost religious debates. I know I say this way too often:I’ll cover this topic in a future post ;)), but share a few observations of analyzing well-known examples of vulnerabilities that led to guest-to-host-escape scenarios. The following table provides an overview of the vulnerabilities in question:&lt;/p&gt;</description>
    </item>
    <item>
      <title>3 Ways for 3-Letter-Agencies to get your Government Proof, Indecipherable Cloud Text Messages</title>
      <link>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</link>
      <pubDate>Wed, 10 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/3-ways-for-3-letter-agencies-to-get-your-government-proof-indecipherable-cloud-text-messages/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://gritsforbreakfast.blogspot.de/2013/04/encryption-for-cloud-communications-may.html&#34;&gt;gritsforbreakfast blog post&lt;/a&gt; making the rounds on the &lt;a href=&#34;https://mailman.stanford.edu/pipermail/liberationtech/2013-April/008100.html&#34;&gt;Liberation Tech mailing list&lt;/a&gt; about security of Apple’s iMessaging service is gaining quite some attention. The post refers to a &lt;a href=&#34;http://news.cnet.com/8301-13578_3-57577887-38/apples-imessage-encryption-trips-up-feds-surveillance/&#34;&gt;CNET article&lt;/a&gt; on how the iMessage service “stymied attempts by federal drug enforcement agents to eavesdrop” conversations due its end-to-end encryption and commends Apple for protecting the user’s privacy while pointing out that Gmail and Facebook Messaging don’t. However, I disagree on some points of the blog post and therefore want to discuss them here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Thoughts on Cloud Governance, Part 1</title>
      <link>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</link>
      <pubDate>Fri, 05 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/thoughts-on-cloud-governance-part-1/</guid>
      <description>&lt;p&gt;Last week Rapid7 &lt;a href=&#34;https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets&#34;&gt;posted&lt;/a&gt; an interesting analysis of the Amazon S3 storage system: Apparently roughly one out of six S3 buckets (a bucket is, simply said, a kind of folder) is accessible without any authentication mechanism. Accessing those files, the &lt;a href=&#34;http://www.rapid7.com/&#34;&gt;Rapid7&lt;/a&gt; guys were able to download a &lt;a href=&#34;http://www.google.com/search?q=site%3As3.amazonaws.com+filetype%3Axls+password&amp;amp;btnG=Search&amp;amp;client=opera&amp;amp;oe=utf-8&amp;amp;channel=suggest&amp;amp;gbv=1&#34;&gt;wide range of data&lt;/a&gt;, also comprising confidential information such as source code or employee information, comparable to past research for &lt;a href=&#34;http://blog.rootshell.be/2012/05/19/what-are-you-sharing-with-dropbox/&#34;&gt;other platforms&lt;/a&gt; (see also this presentation I gave on some of the &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;biggest Cloud #Fails&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>BPDU Guard: Bringing Down Infrastructures</title>
      <link>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</link>
      <pubDate>Thu, 04 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/bpdu-guard-bringing-down-infrastructures/</guid>
      <description>&lt;p&gt;As you may already be familiar with some of our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;previous&lt;/a&gt; &lt;a href=&#34;https://www.ernw.de/download/ERNW_Newsletter_41_ExploitingVirtualFileFormats_signed.pdf&#34;&gt;work&lt;/a&gt; which was mainly focused on isolation issues of hypervisors, we also want to present you an issue concerning availability in Cloud environments. This issue was already covered in some of our &lt;a href=&#34;https://www.ernw.de/download/ERNW_DCVI-HypervisorsToClouds.pdf&#34;&gt;presentations&lt;/a&gt;, but will be explained in greater detail in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;In the course of one of our security assessments of a public IaaS Cloud environment, we experienced the following network setting:&lt;/p&gt;</description>
    </item>
    <item>
      <title>BASTA! Spring 2013</title>
      <link>https://insinuator.net/2013/02/basta-spring-2013/</link>
      <pubDate>Thu, 28 Feb 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/02/basta-spring-2013/</guid>
      <description>&lt;p&gt;Yesterday I was giving two presentations about Cloud security at the &lt;a href=&#34;http://basta.net/&#34;&gt;BASTA!&lt;/a&gt; Spring 2013 Security Day. While my presentations covered Microsoft Azure security considerations (which also included a part of the Cloud security approach covered in our &lt;a href=&#34;https://www.troopers.de/agenda13/troopers13-1-day-workshop-auditing-the-cloud/index.html&#34;&gt;workshops&lt;/a&gt;; slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_AzureSec.pdf&#34;&gt;here&lt;/a&gt;) and some major Cloud incidents (suitable to transport different messages about Cloud security in general ;); slides available &lt;a href=&#34;https://www.ernw.de/download/ERNW_BastaSpring13_CloudFails.pdf&#34;&gt;here&lt;/a&gt;), I also saw &lt;a href=&#34;http://leastprivilege.com/&#34;&gt;Dominick’s&lt;/a&gt; very interesting &lt;a href=&#34;https://speakerdeck.com/leastprivilege/windows-8-security-for-developers&#34;&gt;presentation&lt;/a&gt; about security aspects and changes in Windows 8. Inspired by that, we hope to be able to publish another blogpost on those aspects with regard to enterprise environments soon — most likely we won’t find any time for it before &lt;a href=&#34;http://www.troopers.de&#34;&gt;TROOPERS&lt;/a&gt; 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insider Threats in the Cloud</title>
      <link>https://insinuator.net/2013/01/insider-threats-in-the-cloud/</link>
      <pubDate>Sat, 05 Jan 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/01/insider-threats-in-the-cloud/</guid>
      <description>&lt;p&gt;at first a happy new year to all our readers!&lt;br&gt;&#xA;And, of course, to everybody else, too ;-). May 2013 bring good things for you all, in particular (but not only) in the infosec space.&lt;/p&gt;&#xA;&lt;p&gt;At the &lt;a href=&#34;http://www.acsac.org/&#34;&gt;recent ATSAC 2012 conference&lt;/a&gt; a guy from the CERT Insider Threat Center gave a talk on the exact topic. Given that the &lt;a href=&#34;http://www.enisa.europa.eu/activities/risk-management/files/deliverables/cloud-computing-risk-assessment/at_download/fullReport&#34;&gt;ENISA Cloud Computing Risk Assessment&lt;/a&gt; lists “Cloud Provider Malicious Insider” as one of the top eight risks (out of overall 35 risks evaluated) and we just had some discussion about this in a customer environment, this might be of interest for some readers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — FAQ</title>
      <link>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</link>
      <pubDate>Sun, 17 Jun 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/06/vmdk-has-left-the-building-faq/</guid>
      <description>&lt;p&gt;As we are receiving a lot of questions about our &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;VMDK has left the building post&lt;/a&gt;, we’re compiling this FAQ post — which will be updated as our research goes on.&lt;/p&gt;&#xA;&lt;p&gt;** **&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;How does the attack essentially work?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;By bringing a specially crafted VMDK file into a VMware ESXi based virtualization environment. The specific attack path is described &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-follow-up/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;* *&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is a VMDK file?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;A combination of two different types of VMDK files, the plain-text descriptor file containing meta data and the actual binary disk file, describes a VMware virtual hard disk. A detailed description can be found &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building/&#34;&gt;here&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>VMDK Has Left the Building — Some Nasty Attacks Against VMware vSphere 5 Based Cloud Infrastructures</title>
      <link>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</link>
      <pubDate>Thu, 24 May 2012 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2012/05/vmdk-has-left-the-building-some-nasty-attacks-against-vmware-vsphere-5-based-cloud-infrastructures/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Update #1:&lt;/strong&gt; Slides are available for download &lt;a href=&#34;http://www.insinuator.net/2012/05/vmdk-has-left-the-building-slides-available/&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;In the course of our ongoing &lt;a href=&#34;http://www.troopers.de/archives/troopers12/agenda/auditing-the-cloud-workshop/&#34;&gt;cloud security research&lt;/a&gt;, we’re continuously thinking about potential attack vectors against public cloud infrastructures. Approaching this enumeration from an external customer’s (speak: attacker’s 😉 ) perspective, there are the following possibilities to communicate with and thus send malicious input to typical cloud infrastructures:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Management interfaces&lt;/li&gt;&#xA;&lt;li&gt;Guest/hypervisor interaction&lt;/li&gt;&#xA;&lt;li&gt;Network communication&lt;/li&gt;&#xA;&lt;li&gt;File uploads&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As there are already several successful exploits against management interfaces (e.g. &lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;here&lt;/a&gt; and &lt;a href=&#34;http://www.insinuator.net/2011/07/the-key-to-your-datacenter/&#34;&gt;here&lt;/a&gt;) and guest/hypervisor interaction (see for example &lt;a href=&#34;http://www.vmware.com/security/advisories/VMSA-2012-0009.html&#34;&gt;this one&lt;/a&gt;; yes, this is the funny one with that ridiculous recommendation “Do not allow untrusted users access to your virtual machines.” ;-)), we’re focusing on the upload of files to cloud infrastructures in this post. According to our experience with major &lt;em&gt;Infrastructure-as-a-Service&lt;/em&gt; (IaaS) cloud providers, the most relevant file upload possibility is the deployment of already existing virtual machines to the provided cloud infrastructure. However, since a quick additional research shows that most of those allow the upload of VMware-based virtual machines and, to the best of our knowledge, the VMware virtualization file format was not analyzed as for potential vulnerabilities yet, we want to provide an analysis of the relevant file types and present resulting attack vectors.&lt;/p&gt;</description>
    </item>
    <item>
      <title>All Your Clouds are Belong to us</title>
      <link>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</link>
      <pubDate>Mon, 24 Oct 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/10/all-your-clouds-are-belong-to-us/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.nds.rub.de/media/nds/veroeffentlichungen/2011/10/22/AmazonSignatureWrapping.pdf&#34;&gt;This&lt;/a&gt; is a _very_ interesting paper just published by some researchers (mainly) from RUB (Ruhr-University Bochum). Here’s the abstract:&lt;/p&gt;&#xA;&lt;p&gt;“Cloud Computing resources are handled through control interfaces. It is through these interfaces that the new machine images can be added, existing ones can be modied, and instances can be started or ceased. Effectively, a successful attack on a Cloud control interface grants the attacker a complete power over the victim’s account, with all the stored data included.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Key to your Datacenter</title>
      <link>https://insinuator.net/2011/07/the-key-to-your-datacenter/</link>
      <pubDate>Tue, 19 Jul 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/07/the-key-to-your-datacenter/</guid>
      <description>&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;During our ongoing research on the security of cloud service providers and cloud based applications, we performed a regular audit of our &lt;a href=&#34;http://aws.amazon.com&#34; title=&#34;AWS&#34;&gt;AWS&lt;/a&gt; account password. Thinking of &lt;a href=&#34;http://www.wired.com/threatlevel/2009/07/kaminsky-hacked/&#34;&gt;popular incidents&lt;/a&gt; and evergreens in &lt;a href=&#34;%20http://88.84.128.30/~isnochys/wordpress/wp-content/bruteforce.jpg&#34;&gt;attack vectors&lt;/a&gt;, we were wondering which consequences an online bruteforce attack on our AWS password would have. So we decided to perform a bruteforce attack against our own account. Analyzing the login process of AWS, the following requirements for the bruteforce tool to be used could be derived:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extracting Data from Very Large Pcap Files – Part 3: Pcap Filtering in the Cloud</title>
      <link>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</link>
      <pubDate>Mon, 13 Jun 2011 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-part-3-pcap-filtering-in-the-cloud/</guid>
      <description>&lt;p&gt;This is the third (and last) part of the series (parts &lt;a href=&#34;http://www.insinuator.net/2011/04/extracting-data-from-very-large-pcap-files-part-1-tools-and-hardware/%20&#34;&gt;1&lt;/a&gt; &amp;amp; &lt;a href=&#34;http://www.insinuator.net/2011/06/extracting-data-from-very-large-pcap-files-%E2%80%93-part-2-results-from-the-local-lab/%20&#34;&gt;2&lt;/a&gt; here). We’ll provide the results from some additional tests supported by public cloud services, namely AWS (Amazon Web Services).&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Lab Setup&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The Amazon Elastic Compute Cloud (short: EC2) provides a flexible environment for the on demand provisioning of virtual machines of different performance levels. For our lab setup, a so-called extra large instance was used. According to Amazon, the technical specs are the following:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud needn’t be daunting | Guide to legal aspects for non-legals</title>
      <link>https://insinuator.net/2010/12/cloud-neednt-be-daunting-guide-to-legal-aspects-for-non-legals/</link>
      <pubDate>Thu, 23 Dec 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/12/cloud-neednt-be-daunting-guide-to-legal-aspects-for-non-legals/</guid>
      <description>&lt;p&gt;The British Standards Institution recently published “Cloud Computing. A Practical Introduction to the Legal Issues”. I ordered an electronic copy yesterday (I did that &lt;a href=&#34;http://shop.bsigroup.com/en/ProductDetail/?pid=000000000030215581&#34;&gt;here&lt;/a&gt;, for GBP 30) and after a first glance can say there’s lots of valuable information in it.&lt;/p&gt;&#xA;&lt;p&gt;Merry christmas to everybody, have some peaceful and relaxing days&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
    <item>
      <title>Trust &amp; Control in the Age of Virtualization and the Cloud</title>
      <link>https://insinuator.net/2010/11/trust-control-in-the-age-of-virtualization-and-the-cloud/</link>
      <pubDate>Wed, 17 Nov 2010 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2010/11/trust-control-in-the-age-of-virtualization-and-the-cloud/</guid>
      <description>&lt;p&gt;Two days ago I gave the keynote at an industry event, reflecting on the changing role of traditional security controls in the age of virtualization and the cloud. As this was an updated version of the stuff distributed in the conference proceedings, some people have asked for it. Voilà, &lt;a href=&#34;http://www.ernw.de/content/e7/e181/e1612/download1614/ERNW_LANline_VirtCloudSec_Keynote_ger.pdf&#34;&gt;here we go&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;have a good one,&lt;/p&gt;&#xA;&lt;p&gt;Enno&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
