Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
dTub
Скачать

The AWS ECS Jailbreak: How a Container Stole Admin Keys

Автор: VoiceFromTheDark

Загружено: 2025-12-18

Просмотров: 70

Описание:

Dive deep into the critical AWS ECS vulnerability presented at Black Hat USA. This is a full documentary breakdown of "ECS-cape – Hijacking IAM Privileges in Amazon ECS" by researcher Naor Haziz of Sweet Security.

🔍 In this video, we explain:
• The technical flaw that lets a low-privileged container steal AWS admin keys.
• The step-by-step attack flow: from IMDS to credential harvesting.
• Why AWS stated this was "not a security concern" and how the documentation was forced to change.
• Practical mitigations you MUST implement to secure your ECS clusters.

This video translates the complex 103-slide presentation into a clear, accessible guide for cloud engineers, security professionals, and anyone curious about cloud security risks.

📚 Research & Original Materials:
All credit for this discovery goes to Naor Haziz and Sweet Security.

• Original Black Hat Briefings Page: https://www.blackhat.com/us-25/briefi...
• Researcher's Blog Post: https://www.sweet.security/blog
• Researcher's Personal Site: https://naorhaziz.com/
• Official Proof-of-Concept (GitHub): https://github.com/naorhaziz/ecscape
• Connect with the Researcher (LinkedIn):   / naorhaziz  

🛡️ *Chapters / Timestamps:*
0:00 - The Shocking Vulnerability
1:30 - Understanding ECS, IAM, and the Security Model
5:45 - How the Discovery Was Made
8:20 - The ECScape Attack: A 6-Step Breakdown
15:10 - Live Impact and Stealthy Attribution
18:05 - AWS's Official Response & The Docs Change
20:15 - How to Defend Your Cloud (4 Key Strategies)
23:00 - Final Summary & The Shared Responsibility Model


Video Narration: Suchita Subedi
Research & Original Work: Naor Haziz / Sweet Security

⚠️ Disclaimer: This content is for educational and defensive security purposes only. All information is based on publicly disclosed research from Black Hat USA. Always follow AWS best practices and conduct security testing only in your own environments with proper authorization.

#AWS #EC2 #ECS #CloudSecurity #CyberSecurity #Hacking #BlackHat #PrivilegeEscalation #Documentary #SweetSecurity #Tutorial #AWSECS #Jailbreak

Warm Memories - Emotional Inspiring Piano by Keys of Moon |   / keysofmoon  
Attribution 4.0 International (CC BY 4.0)
https://creativecommons.org/licenses/...
Music promoted by https://www.chosic.com/free-music/all/

#AWS #EC2 #ECS #CloudSecurity #CyberSecurity #Hacking #BlackHat #PrivilegeEscalation #Documentary #SweetSecurity #Tutorial

The AWS ECS Jailbreak: How a Container Stole Admin Keys

Поделиться в:

Доступные форматы для скачивания:

Скачать видео mp4

  • Информация по загрузке:

Скачать аудио mp3

Похожие видео

Cybersecurity Architecture: Networks

Cybersecurity Architecture: Networks

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

Dark Web РАСКРЫТ (БЕСПЛАТНО + Инструмент с открытым исходным кодом)

Same 128GB but cheaper

Same 128GB but cheaper

Scammer Panics so Fast over Russian Virus

Scammer Panics so Fast over Russian Virus

Почему спагетти-код лучше чистой архитектуры

Почему спагетти-код лучше чистой архитектуры

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)

Cybersecurity Architecture: Five Principles to Follow (and One to Avoid)

Top 10 FREE OSINT tools (with demos) for 2024 - And FREE OSINT course!

Top 10 FREE OSINT tools (with demos) for 2024 - And FREE OSINT course!

Скрытый шпион вашего компьютера с Windows 11: тёмная правда о чипах TPM

Скрытый шпион вашего компьютера с Windows 11: тёмная правда о чипах TPM

Sting - Shape of My Heart || Sylwester z Dwójką 2025

Sting - Shape of My Heart || Sylwester z Dwójką 2025

Can Modern Linux Fit on a 1.44mb Floppy?

Can Modern Linux Fit on a 1.44mb Floppy?

Sting - Every Breath You Take || Sylwester z Dwójką 2025

Sting - Every Breath You Take || Sylwester z Dwójką 2025

OSINT tools to track you down. You cannot hide (these tools are wild)

OSINT tools to track you down. You cannot hide (these tools are wild)

Единственный безопасный способ использования Windows 11 — навсегда удалить учетную запись Microso...

Единственный безопасный способ использования Windows 11 — навсегда удалить учетную запись Microso...

If I had to start over...which IT path would I take?

If I had to start over...which IT path would I take?

what's your DREAM job?

what's your DREAM job?

18 Weird and Wonderful ways I use Docker

18 Weird and Wonderful ways I use Docker

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

How to Hide in Plain Sight: Next-Level Digital Privacy | Ivan Banov at BSidesCache 2025

The Windows 11 Crisis

The Windows 11 Crisis

Orędzie noworoczne Prezydenta RP

Orędzie noworoczne Prezydenta RP

I'll never use n8n the same......

I'll never use n8n the same......

© 2025 dtub. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]