Skip to main content

This new open-source tool is hunting for public AWS S3 buckets to spy on

Cloud misconfigurations are one of the biggest causes of data breaches these days, and one security researcher has now set out to fix it with a new tool.

Built on Python, S3crets Scanner allows security researchers and analysts to look for “secrets” that companies exposed to the public, by mistake, through their company’s AWS S3 storage buckets.

As explained by BleepingComputer, secrets include authentication keys, access tokens, or API keys, all of which can be used by threat actors to deal plenty of damage. For example, these secrets can be used to access the company’s corporate network and endpoints, which could result in data theft, malware infections, or even ransomware attacks. 

Targeting PII

The tool was built by security researcher Eilon Harel to only look for secrets exposed by mistake. It does so by only scanning S3 buckets that have specific configurations set to false, such as “BlockPublicAcls”, “BlockPublicPolicy”, “IgnorePublicAcls”, and “RestrictPublicBuckets”. Any other buckets are filtered out. 

Buckets that match the above criteria will be downloaded as text files, and scanned using the Trufflehog3 tool which checks for credentials and private keys on S3 buckets, but also GitHub, GitLab, and filesystems. Harel created a unique set of rules for Trufflehog3, which targets personally identifiable information (PII) exposure, as well as internal access tokens. 

Harel believes the tool can help businesses expose fewer secrets, consequently suffering fewer data leaks and similar cybersecurity incidents. He also believes it can be used for white-hat operations, as researchers can scan publicly accessible buckets for misconfigurations and notify the businesses before bad actors.

A multi-cloud environment is essential for businesses these days, but securing data in such a system is one of the biggest challenges they face. A recent report by cybersecurity experts Radware states that 70% of senior execs, DevOps leaders, and other seniors, aren’t confident they can properly secure both on-prem and multi-cloud environments. 

Via: BleepingComputer

Source: TechRadar

Popular posts from this blog

Keep your Oculus Quest controllers going strong with these batteries

The Touch Controllers for the Oculus Quest 2 ship with one disposable AA battery each, but once those run out of juice, you should invest in the best Oculus Quest 2 replacement batteries to fill in for them. While the Touch Controllers last much longer than the headset's limited battery, it's still wise to invest in some rechargeable batteries or a stack of disposable batteries to stop your VR sessions from getting disrupted. Here are the batteries and chargers we recommend for your Oculus Touch controllers. Best rechargable batteries + charger Panasonic K-KJ55MCA4BA 3 Hour Quick Charger with 4 AA eneloop Rechargeable Batteries Staff Pick These rechargeable batteries store up to 2,000 mAh of power and can be recharged up to 2,100 times. They can be charged completely from dead or partially charged without damaging the energy storage memory. We recommend buying them with the quick charger accessory, which will get your AAs recharged in no time, but you can also purchas

Uber Eats exits seven markets, transfers one as part of competitive retooling

Uber Eats is pulling out of a clutch of markets — shuttering its on-demand food offering in the Czech Republic, Egypt, Honduras, Romania, Saudi Arabia, Uruguay and Ukraine. It’s also transferring its Uber Eats business operations in the United Arab Emirates (UAE) to Careem, its wholly owned ride-hailing subsidiary that’s mostly focused on the Middle East. “Consumers and restaurants using the Uber Eats app in the UAE will be transitioned to the Careem platform in the coming weeks, after which the Uber Eats app will no longer be available,” it writes in a regulatory filing detailing the operational shifts. “These decisions were made as part of the Company’s ongoing strategy to be in first or second position in all Eats markets by leaning into investment in some countries while exiting others,” the filing adds. An Uber spokesman said the changes are not related to the coronavirus pandemic but rather related to an ongoing “strategy of record” for the company to hold a first or s

This popular open-source web server has some serious security flaws

OpenLiteSpeed Web Server, a globally popular open-source web server , was carrying a couple of high-severity vulnerabilities, experts have warned. Threat actors that managed to exploit these flaws would have been given full privilege remote code execution capabilities, noted researchers from Unit 42, Palo Alto Networks’ cybersecurity research arm.  The team found OpenLiteSpeed Web Server carried three high-severity vulnerabilities, namely CVE-2022-0073 (an 8.8 severity score, high-severity remote code execution flaw), CVE-2022-0074 (an 8.8 high-severity privilege escalation flaw), and CVE-2022-0072 (a 5.8, medium-severity directory traversal flaw). The vulnerabilities also affected the enterprise version, LiteSpeed Web Server. Patch ready Unit 42 has notified LiteSpeed Technologies of its findings which has, subsequently, patched the flaws, and released new versions of the server, urging users to update their software immediately.  Organizations using OpenLiteSpeed versions 1.5.1

These Android games support Bluetooth controllers and they're better for it

Gaming is simply better with a controller in your hands. Gaming on Android typically requires you to settle for using touchscreen controls. However, some gracious game developers take the time and effort to add support for Bluetooth gamepads— and we love them for it. Since so few games provide this feature, we've taken the time to test and compiled our list of the best games that let you play with the best Bluetooth controller in your hands. We'd also recommend getting a Style Ring or PopSocket which can help prop your phone up at a good angle for gaming. You might recognize some of these games from the best Android games roundup and for good reason. But you're here for the best games with controller support, after all, so here I present to you the best you can find on the Play Store. The games Call of Duty Mobile GRID Autosport Tesla vs Lovecraft Evoland 2 Horizon Chase World Tour Riptide GP: Renegade Modern Combat 5: Blackout GTA: San Andreas Oceanhor