This
is a _very_ interesting paper just published by some researchers (mainly) from
RUB (Ruhr-University Bochum). Here’s the abstract:
“Cloud Computing resources are handled through control interfaces. It is through
these interfaces that the new machine images can be added, existing ones can be
modied, and instances can be started or ceased. Effectively, a successful attack
on a Cloud control interface grants the attacker a complete power over the
victim’s account, with all the stored data included.
During our ongoing research on the security of cloud service providers and cloud
based applications, we performed a regular audit of our
AWS account password. Thinking of
popular incidents
and evergreens in
attack vectors,
we were wondering which consequences an online bruteforce attack on our AWS
password would have. So we decided to perform a bruteforce attack against our
own account. Analyzing the login process of AWS, the following requirements for
the bruteforce tool to be used could be derived:
This is the third (and last) part of the series (parts
1
&
2
here). We’ll provide the results from some additional tests supported by public
cloud services, namely AWS (Amazon Web Services).
Lab Setup
The Amazon Elastic Compute Cloud (short: EC2) provides a flexible environment
for the on demand provisioning of virtual machines of different performance
levels. For our lab setup, a so-called extra large instance was used. According
to Amazon, the technical specs are the following:
The British Standards Institution recently published “Cloud Computing. A
Practical Introduction to the Legal Issues”. I ordered an electronic copy
yesterday (I did that
here, for
GBP 30) and after a first glance can say there’s lots of valuable information in
it.
Merry christmas to everybody, have some peaceful and relaxing days
Two days ago I gave the keynote at an industry event, reflecting on the changing
role of traditional security controls in the age of virtualization and the
cloud. As this was an updated version of the stuff distributed in the conference
proceedings, some people have asked for it. Voilà,
here we go.