top | item 16119849

(no title)

scottpiper | 8 years ago

Thank you for posting this, but doesn't "Show HN" mean you're linking to something you've made? I'm the creator of flaws.cloud

discuss

order

spydum|8 years ago

Scott, Thanks for creating this! Julien from Mozilla referred this to me back at AppSec and I have been using it as a devops security primer for folks in my org since. Really clever teaching tool. I've had it on my mind to create an Azure equivalent when time permits!

graystevens|8 years ago

Thanks for putting this together Scott - I remember running through the exercises a year or so ago and realising how awesome some of these mistakes are. I ended up turning the S3 bucket stuff into a conference presentation, after bruteforcing *.s3.amazonaws.com for valid buckets, and checking their permissions/ACLs.

Great for bug bounties, or in UpGuard’s situation, a tonne of publicity from private data being accessible from public buckets.