Slides for 3 cloud security talks from Hacker Summer Camp
1️⃣ Kicking in the Door to the Cloud: Exploiting Cloud Provider Vulnerabilities for Initial Access
- By @Frichette_n
https://t.co/HkznHIo3NF
2️⃣ Exploiting Common Vulnerabilities in AWS environments
- By @sethsec
https://t.co/MPnKSNYXix
3️⃣ Cloud Tripwires
- By @jenkohwong
https://t.co/E77QpMbalQ
@arshadkazmi42@Hacker0x01 How do you negotiate with companies? Do you just report it to them and am then ask for bounty? Or first negotiate the bounty amount and then disclose?
😈 How to protect Evilginx using Cloudflare and HTML Obfuscation
* Cloudflare's 'Under Attack Mode'
* Geo-block connections outside of you/target
* Use another server as a redirector
* Use meta refresh and HTML obfuscation
By @jackbutton_#redteam
https://t.co/QpiKG9QCiW
🔥 Having some hard time with Initial Access during your gigs?
Join the February☢️Modern Initial Access and Evasion Tactics☢️ training round and dive deep into lesser known arcanes of common file vectors!
Class trusted by many experienced fellow RTerz!
https://t.co/ea1pA5VfJZ
How Secrets Leak in CI/CD Pipelines
Secrets leak in CI/CD pipelines routinely. CI/CD workflows typically require developers to provide valid credentials for the 3rd party resources their pipeline interacts with.
👀https://t.co/npwJPIocj2 #DevOps#Kubernetes#CICD