Amazon AWS Security Risks
Amazon AWS provides a great opportunity for the companies to reduce the costs in their IT infrastructure and increase the speed they can release their products to the market.
Amazon AWS provides a great opportunity for the companies to reduce the costs in their IT infrastructure and increase the speed they can release their products to the market. Amazon AWS contains a large number of resources, such as Infrastructure-as-a-Service (called EC2), file storage (S3 buckets), Database-as-a-service (RDS) and many others. The number is growing every day and the value increases significantly. Almost all startups and companies now consider Amazon AWS to host their IT infrastructure.
To make an appropriate decision to use Amazon AWS cloud or not the companies need to fully understand the risks introduced by using this technology. The risks landscape is very different from traditional IT infrastructure, when all the critical system and applications are located behind the corporate firewall in internal network. Now the infrastructure located in the Cloud and requires different protection.
Below are the common risks introduced by the adopting Amazon AWS Cloud:
Unauthorised access to the Cloud Management Console.
Description: The administrator or Amazon AWS Account owner has full control over the cloud resources. He or she can delete all the servers just by clicking the button. If the administrator is not fully understand the technical background, he or she can open the firewall rules to allow all the traffic going in and out of Amazon AWS account. The hackers can potentially brute force / guess/ steal the password and connect to the console. If a hacker gets control over the account, the availability and integrity of the systems can be affected.
Risk: High
Likelihood: High (by default the account is protected by only password)
Impact: High (all the servers can be affected)Mitigation controls: Amazon AWS can provide additional protection for an Amazon AWS account: two factor authentication. The administrator can use their mobile phone with Google Authenticator installed to increase the security of the account. Two factor authentication is not enabled by default and requires additional configuration.
Poor access management process.
Description: The Amazon AWS Management console is available from anywhere in the world. Obviously it provide a great flexibility for the users, but also presents a huge risk. If a company doesn’t have strong access management process, the terminated employee will probably still have access to the console. He or she will be able to connect from home, internet café or even competitor. Many companies have Identity and Access Management (IAM) system implemented for their internal systems, but Amazon AWS console not always integrated with it.
Risk: High
Likelihood: Almost certain (if a company has a large number of users)
Impact: High (terminated users may cause significant damage)Mitigation controls: The companies need to review the users on the regular basis. It may be difficult the one company has multiple Amazon AWS accounts as Amazon doesn’t provide centralised console at this stage. Another option is to integrate Amazon AWS with IAM system or Active Directory, but it requires significant investment.
Weak firewall rules.
Description: By default, when you create an Amazon EC2 instance the Amazon will propose the default firewall rules (Amazon calls them the “security groups”) to access the instance. For Linus based instances it will be port 22 (secure shell) and probably ports 80 and 443 for the web server. For Windows instances they will be port 3389 (Remote Desktop) and ports 80 and 443 for the web application. By default, all internet will have access to this ports (source is 0.0.0.0/0). The hackers will probably try to brute force the password for SSH or RDP or use known exploit to get in.
Risk: Medium
Likelihood: Almost certain (not many people change the default rule set)
Impact: Medium (the SSH access by default is configured to use private/public key and Windows password is relatively strong)Mitigation controls: The administrators or security professionals need to constantly audit the firewall rules to make sure the remote access is configured for particular source IP addresses. The IP restriction will reduce the risk of compromise significantly.
The above risks are just an example of what the companies should look at when adopting Amazon AWS cloud. The internal security department or systems administrators should perform the comprehensive security assessment of the environment before putting critical application into the cloud. If a company doesn’t have necessary skills to do it “in-house”, Cloud Guardian will help. Cloud Guardian staff will perform the risks assessment of your environment, propose the best mitigation controls and integrate them with our monitoring system to make sure your environment is safe. Moreover, we’ll help you to secure all your Amazon AWS accounts from single interface. Contact us for more details.
Enjoy AWS Security like Never Before
If you want to secure your Amazon AWS accounts, Cloud Guarding is where your search ends. As a unique tool performing Amazon AWS risks assessment, Cloud guardian not only monitors changes across multiple Amazon AWS accounts but also manages multiple Amazon AWS accounts.
This way Cloud Guardian allows users to have absolute control over who is granted or denied access to their Amazon AWS accounts. Cloud Guardian also facilitates the security groups by ensuring that they are configured properly and ensures that all instances of a cloud are well protected.
Another SSL/TLS Vulnerability
Secure Sockets Layer or SSL pertains to the standard security technology utilized mainly for establishing an encrypted link between a browser and a server. This link makes sure that all essential data are transferred between browsers and web servers in an integral and private manner. SSL is a widely known digital networking protocol managing client authentication, server authentication and the encrypted communication between clients and servers.
The Transport Layer Security or TLS, on the other hand, pertains to the protocol that completely ensures privacy between exclusive communication applications and their respective users online. When a client and a server interact or communicate, this technology makes sure that there is no third-party tampering or eavesdropping with the messages. The Transport Layer Security is said to be the successor of Secure Sockets Layer of SSL.
Freak-Analyzed and Defined
Freak attacks take advantage of RSA Export major clippers that are designed to be weaker on purpose so that they will fit in the borders of US Encryption controls of export of previous years. The deconstruction of attack is composed of three steps which are outlined below:
- Create a Man at the Midst of the Scenario
This is as simple as going to a public Wi-Fi area and setting up the proxy. Modify the traffic of clients to request the main Export RSA key.
- Factor 512-Bit RSA Export Key Quickly In Order To Decrypt The Main Secret
There are reliable services specifically for this pursuit. One of these is using the online services of Amazon which only takes about 7 to 12 hours for one hundred dollars. Modify or monitor the traffic that is going between the unconfirmed server and vulnerable client in plain text.
You might have caught caution in the third step which is unconfirmed server and vulnerable client. The server must be willing to negotiate the weaker export key or must host the susceptible third-party software like the Facebook JavaScript SDK, sites that include Facebook’s login button and like button or Apache’s Open SSL and mod_SSL versions. Some susceptible devices and clients can include the Safari on any Apple device.
What You Need to Do to Ensure Ultimate Personal Protection
Freak attacks are getting widespread more than you previously thought. Browsers using OpenSSL are susceptible and this includes Android browsers and perhaps Samsung-derived browsers called “Internet.” Similarly, Apple’s exclusive implementation of TLS, known as Secure Transport, puts OS X and also Safari at risk.
The best thing that needs to be done now is to ensure your protection against this vulnerability. However, you need to make sure that you have clear ideas on how to configure this for your usual privacy. If you truly want to protect yourself, this can be done in simple steps.
If you are running a web server, you need to disable support for all the export suites, but you also need to check and ensure that you are not utilizing any known unsecure ciphers. Enabling support also needs to be done to forward exclusivity or secrecy.
Magento Vulnerability - Check your web sites now
Magento platform is a popular eCommerce framework used by the organisation all over the world to create the Online shops.
The researchers from Check Point discovered the critical security issues, which could potently allow the remote compromise of a Magento based web site and gaining unauthorized access to the customer and credit card information. See the full post here: http://blog.checkpoint.com/2015/04/20/analyzing-magento-vulnerability/ . The vulnerability is currently affecting thousands of online stores.
Technical Details
Three vulnerabilities were discovered by the Check Point team:
CVE-2015-1398 - An authentication bypass vulnerability was reported in Magento component. The vulnerability is due to a user controlled parameter affecting the login mechanism. A remote attacker can exploit this issue by sending a specially crafted HTTP request to a vulnerable system. Successful exploitation may allow the attacker to gain access to a target system.
CVE-2015-1397 - An SQL injection vulnerability has been reported in Magento component. Successful exploitation of this vulnerability would allow a remote attacker to execute arbitrary SQL commands on the affected system.
CVE-2015-1399 - A remote file inclusion vulnerability has been reported in Magento component. The vulnerability is due to lack of sanitization for user-supplied data. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code on the affected system.
What should you do
Check your Magento implementation using our Trial Web Site Assessment Service and see if you are vulnerable. If yes, apply the designated patch SUPEE-5344 released by Magento as soon as possible.
SSL 3 is dead, killed by the POODLE attack
The POODLE Attack (CVE-2014-3566)
Update (8 Dec 2014): Some TLS implementations are also vulnerable to the POODLE attack. More information in thisfollow-up blog post.
After more than a week of persistent rumours, yesterday (Oct 14) we finally learned about the new SSL 3 vulnerability everyone was afraid of. The so-called POODLE attack is a problem in the CBC encryption scheme as implemented in the SSL 3 protocol. (Other protocols are not vulnerable because this area had been strengthened in TLS 1.0.) Conceptually, the vulnerability is very similar to the 2011 BEAST exploit. In order to successfully exploit POODLE the attacker must be able to inject malicious JavaScript into the victim's browser and also be able to observe and manipulate encrypted network traffic on the wire. As far as MITM attacks go, this one is complicated, but easier to execute than BEAST because it doesn't require any special browser plugins. If you care to learn the details, you can find them in the short paper or in Adam Langley's blog post.
What Now?
POODLE is a protocol-level vulnerability that can't be easily fixed. Although it might be possible to attempt a BEAST-style mitigation, it seems that browser vendors are not interested in that approach. Adam said Chrome won't pursue that direction. Firefox said they would disable SSL 3 in Firefox 34. And that's great news. Traditionally we struggle with letting go of old protocols. Because SSL 3 is not very widely used and POODLE is serious enough, it seems that we'll be able to retire this old protocol version soon. In fact, some CDNs have already disabled it.
What You Should do
You can look at this problem from two perspectives. As a user, you want to protect yourself from attacks, and the best way to do that is to disable SSL 3 in your browser. (Instructions are easy to find online.) The updated SSL Labs Client Test will tell you if your change was successful.
As a web site operator, you should disable SSL 3 on your servers as soon as possible. You need to do this even if you support the most recent TLS version because an active MITM attacker can force browsers to downgrade their connections all the way down to SSL 3, which can then be exploited. In normal operation, SSL 3 shouldn't needed by the vast majority of sites. Although it's likely that there's a long tail of clients that don't support anything better, Internet Explorer 6 on Windows XP is potentially the biggest user segment that still relies on SSL 3. Options are to guide users to manually enable TLS 1.0 (IE6 supports it, but not by default) or upgrade to other browsers. In the short term, it's possible to mitigate POODLE by avoiding using CBC suites with SSL 3, but that involves relying on a certain insecure stream cipher whose name no one wants to mention. I don't recommend this approach.
POODLE wouldn't be as serious without the ability of the active network attacker to downgrade modern browsers down to SSL 3. There's a solution to this problem, via the TLS_FALLBACK_SCSV indicator that must be supported by clients and servers in order to be effective. Google implemented this feature in February (in Chrome and in their web sites) and has been successfully using since. Mozilla said Firefox will support the indicator in early 2015. A new version of OpenSSL has just been released, which includes support for the SCSV. The support might be backported to various Linux distributions. For best results, support also needs to be added to other major browsers. Once that happens, the POODLE attack surface will be much smaller; it will affect only the users with older browsers.
For detailed guidance on how to disable SSL 3 in various servers and browsers, head to Scott Helme's blog post. Qualys customers should go here to learn how to configure reports to find systems that use SSL 3.