iPad Pro w/ Magic KB, Surface Go 2, or $350 Off with OnDemand Training - Register Now

Webcasts

To attend this webcast, login to your SANS Account or create your Account.

This webcast has been archived. To view the webcast login into your SANS Portal Account or create an account by clicking the "Get Registered" button on the right. Once you register, you can download the presentation slides below.

Attacking and Defending Cloud Metadata Services

  • Wednesday, October 30, 2019 at 10:30 AM EDT (2019-10-30 14:30:00 UTC)
  • Eric Johnson

You can now attend the webcast using your mobile device!

  

Overview

Cloud Metadata Services have been exploited by attackers in order to gain direct access to an organizations cloud resources. The Capital One breach notification published in July put a spotlight on the metadata service and its weaknesses. Join Eric Johnson for a walk through of the publicly available information from the breach. We will demonstrate how the attacker compromised AWS instance metadata credentials, gained access to privileged resources, and exfiltrated data from the account. The conversation then shifts to a post mortem discussion about cloud security controls that could have prevented or limited the blast radius of the attack.

Speaker Bio

Eric Johnson

Eric Johnson, Principal Security Engineer at Puma Security and Principal SANS Instructor, focuses on cloud security, DevSecOps automation, and building static analysis tools. His experience includes application security automation, cloud security reviews, static source code analysis, web and mobile application penetration testing, secure development lifecycle consulting, and secure code review assessments.

Need Help? Visit our FAQ page or email webcast-support@sans.org.

Not able to attend a SANS webcast? All Webcasts are archived so you may view and listen at a time convenient to your schedule. View our webcast archive and access webcast recordings/PDF slides.