AWS RDS Vulnerability Leads to AWS Internal Service Credentials
blog.lightspin.io
blog.lightspin.io
The fact AWS overlooked access controls allowing a customer to reach system files, let alone the STS token, on a multi-tenant service is worrisome.
I'd imagine it's only scoped to a single customer account but I'm curious what it gives access to.
Wish I could do this all day long...
Aside, the fact that it took almost 4 months to remediate all accounts is crazy. AWS and cloud in general was supposed to make it dumb easy to upgrade, patch and maintain infra software in production.
RDS, simple as it may seem on the surface, is one of the things I'm most grateful for in AWS.
Aurora might be a different situation, not sure.
Easy doesn't mean fast.
I'm simply curious, is this standard (or a popular) etiquette among security researchers?
Once you get creds, you stop and report. You don't use, you don't enumerate, you dont do shit with them.
Getting and reporting is good faith. Getting and using is likely starting a felony case.