У нас вы можете посмотреть бесплатно Capital One's $200M Cloud Data Breach или скачать в максимальном доступном качестве, видео которое было загружено на ютуб. Для загрузки выберите вариант из формы ниже:
Если кнопки скачивания не
загрузились
НАЖМИТЕ ЗДЕСЬ или обновите страницу
Если возникают проблемы со скачиванием видео, пожалуйста напишите в поддержку по адресу внизу
страницы.
Спасибо за использование сервиса ClipSaver.ru
How a random ex-AWS employee managed to get into the AWS account of Capital One unnoticed using a fairly low-skill attack. Sources: https://www.justice.gov/media/1019711... https://blog.appsecco.com/an-ssrf-pri... https://krebsonsecurity.com/2019/08/w... https://www.researchgate.net/publicat...\ https://www.cnet.com/news/politics/am... https://threatpost.com/capital-one-br... Assumptions: 1:35 This is not the actual Github file, we just know there were three commands (see source 1: https://www.justice.gov/media/1019711.... I added the extra export stuff to illustrate how credentials can be loaded without explaining it directly since that is pretty irrelevant info 7:58 We don't know if the role actually had read permissions for everything (wildcard resource) but let's be honest it probably did. Chapters: 0:00 Day of the Incident 2:18 The 3 Commands 4:32 Who's at fault? 5:21 Capital One's vulnerabilities 8:14 The hacker's identity 8:57 Lessons learned Music, all from Creator Music: Impact Prelude, Kevin Macleod Switch it Up, Silent Partner Running Errands, TrackTribe Dumb as a Box, Dan Lebowitz Twitter: / kevinfaang Instagram: / kevinfaang_yt