ISC StormCast for Tuesday, March 12th, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 12 March 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, March 12, 2020, |
| 0:03.9 | edition of the Sandsenet Storm Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
| 0:13.7 | And we got yet another great post by one of our undergraduate interns here from the Sands. |
| 0:20.4 | combeck took a look at |
| 0:24.9 | what happens if you are exposing your aWS API keys now he did two experiments the first one |
| 0:32.0 | was just leaking the API key via a website secondly he then leaked the API key via a website. Secondly, he then leaked the API key via a public GitHub repository. |
| 0:42.8 | In order to detect what happened to the API key, he did use Canary tokens. Canary tokens allow you |
| 0:50.4 | to then receive an email whenever a particular API key is used. |
| 0:56.7 | They have been quite popular. |
| 0:58.0 | You can also attach them to PDFs or Word documents and the like. |
| 1:03.1 | In this particular case, the first experiment where he leaked the API key via the website, via a configuration file on the site. |
| 1:14.2 | It was used within about three days. |
| 1:18.8 | Now, not really clear who used it. |
| 1:20.8 | The attacker did use a proton VPN provider in order to obfuscate the actual source of the request. |
| 1:31.0 | Secondly, when he published it on GitHub, the key was used pretty much immediately. |
| 1:38.0 | However, their things were a little bit different. |
| 1:41.0 | The number one requester was actually a researcher in an organization that |
| 1:47.1 | proactively scans GitHub repositories for Leakeez. Git Guardian was the requester here. |
| 1:54.2 | I'm a little bit odd that actually the emails coming in whenever the key was accessed were so excessive that it actually caused |
| 2:03.5 | some email issues for no one and he had to kind of then discontinue the experiment but needless |
| 2:11.4 | to say yes we have already shown and we had another blog post about this last week that if you do leak these configuration |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

