meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, February 27th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 February 2018

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Cloud Tools: AWSBucketDump, Cloudmapper; Selling Mac and "Find my Mac"; iTunes Store Support end for

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, February 27th, 2018 edition of the Sands and the Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:12.0

A common theme in recent breaches was exposed to cloud resources, whether it was a badly secured S3 bucket or whether it was some server

0:26.1

that wasn't configured correctly. But one thing people are really struggling with is sort of

0:33.1

keeping track of all the resources they're pushing in the cloud.

0:37.8

And that's why I want to highlight two interesting tools that hopefully will make this

0:43.9

a little bit easier.

0:46.3

The first one I think is a little bit on the dark side of the gray head scale, but the

0:54.0

AWS bucket dump allows you to sort of brute force

0:57.7

AWS bucket names so what you would do is you would find a list of terms that are

1:04.6

likely used in your company for AWS bucket names and then try to enumerate them and see if any of these buckets exist

1:13.9

and if they are not properly protected.

1:17.7

The tool also allows you to download files that match certain interesting keywords.

1:23.9

That's of course where things definitely get a little bit interesting from sort of

1:29.1

an ethics and legal point of view if you by mistake end up in a bucket that you are not

1:35.0

authorized to read. The second tool cloud mapper comes courtesy of dual apps and it allows you to

1:43.3

draw pretty nice network diagrams for assets in Amazon

1:48.0

Web Services. Now this is clearly a white hat tool in that you first need access to the

1:56.0

account so you do need credentials for a specific AWS account and then you let a shell script

2:02.1

collect all the information from the AWS account and this is then converted into an

2:08.5

HTML file that is viewable in your browser.

2:12.6

Of course, unlike the first tool, this doesn't really track any sort of shadow IT assets.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.