Here's a reminder:
Legacy systems ARE security vulnerabilities. Especially ones using PHP, XML, RPC.
Remember to migrate ALL systems to using @AuthressHQ and not just your cutting edge ones.
A recent find by @OTPHolidays reminds us of this:
openbugbounty.org/reports/180701…
CURRENT ACTIVIY: On October 24, 2021, Network Time Protocol servers using bugged GPSD versions 3.20-3.22 may rollback the date 1,024 weeks—to March 2002—which may cause systems and services to become unavailable or unresponsive. Learn more: bit.ly/30IR0s1
We don't allow malicious actors to discover our customers IAM principals and roles because retrieving that information requires at least knowledge level access permissions.
I recently found a new enumeration vulnerability in AWS. It allows me to identify valid account IDs and any IAM principal in it. I had a call with AWS security, and they say it’s by design. Well then, let’s take a look!