Tuesday, March 31, 2026
City and Coffee
  • Home
  • World
    At least 70 killed, 30 wounded in Haiti gang attack, rights group says | Crime News

    At least 70 killed, 30 wounded in Haiti gang attack, rights group says | Crime News

    Germany’s FM tells President al-Sharaa ‘We stand with Syria’ | Syria’s War

    Germany’s FM tells President al-Sharaa ‘We stand with Syria’ | Syria’s War

    How will the Houthis’ involvement shape the war? | US-Israel war on Iran News

    How will the Houthis’ involvement shape the war? | US-Israel war on Iran News

    Pakistan hosts four-nation bid to encourage US, Iran towards diplomacy | US-Israel war on Iran News

    Pakistan hosts four-nation bid to encourage US, Iran towards diplomacy | US-Israel war on Iran News

    Iran war live: Tehran warns US, Israeli universities; Houthis fire missiles | US-Israel war on Iran News

    Iran war live: Tehran warns US, Israeli universities; Houthis fire missiles | US-Israel war on Iran News

  • US

    Michigan Synagogue Attack Was ‘Inspired by Hezbollah,’ Officials Say

    As Gas Prices Approach $4 a Gallon, Americans Rethink Vacations

    5 Takeaways From the ‘No Kings’ Rallies as the Midterms Heat Up

    Record Number of T.S.A. Employees Called Out on Friday

    ‘No Kings’ Protests Decry Trump and His Agenda

  • Europe
    Most Syrian refugees in Germany expected to return home in three years, Merz says

    Most Syrian refugees in Germany expected to return home in three years, Merz says

    From jammed broadcasts to a blocked website: BBC Russian's 80 years of defiance

    From jammed broadcasts to a blocked website: BBC Russian's 80 years of defiance

    How deepfake porn scandal surrounding TV star rocked Germany

    How deepfake porn scandal surrounding TV star rocked Germany

    Twenty-two migrants die off Greek coast after six days at sea

    Twenty-two migrants die off Greek coast after six days at sea

    Thirteen arrested in joint Scotland and Spain gangland raids

    Thirteen arrested in joint Scotland and Spain gangland raids

  • MENA
    Gaza mother reunited with evacuated baby daughter

    Gaza mother reunited with evacuated baby daughter

    Latin Patriarch will have access to Jerusalem holy site after police stopped entry

    Latin Patriarch will have access to Jerusalem holy site after police stopped entry

    Hundreds in Beirut mourn journalists killed in Israeli strike

    Hundreds in Beirut mourn journalists killed in Israeli strike

    Shops and restaurants in Egypt told to close early as energy crisis deepens

    Shops and restaurants in Egypt told to close early as energy crisis deepens

    Three Lebanese journalists killed in Israeli strike, say broadcasters

    Three Lebanese journalists killed in Israeli strike, say broadcasters

  • APAC
    Shock, sadness and relief in town at centre of Australia's seven-month police manhunt

    Shock, sadness and relief in town at centre of Australia's seven-month police manhunt

    Fugitive Dezi Freeman shot dead by Australian police after seven months in hiding

    Fugitive Dezi Freeman shot dead by Australian police after seven months in hiding

    Maldives tells UK it does not recognise Chagos Islands deal

    Maldives tells UK it does not recognise Chagos Islands deal

    Nepal's ex-PM arrested over fatal protest crackdown

    Nepal's ex-PM arrested over fatal protest crackdown

    Belarus leader gifts rifle to North Korea's Kim as they sign friendship treaty

    Belarus leader gifts rifle to North Korea's Kim as they sign friendship treaty

  • Tech
    Our Favorite Amazon Streaming Stick Is Almost Half Off

    Our Favorite Amazon Streaming Stick Is Almost Half Off

    Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That

    Your Photos Are Probably Giving Away Your Location. Here’s How to Stop That

    A School District Tried to Help Train Waymos to Stop for School Buses. It Didn’t Work

    A School District Tried to Help Train Waymos to Stop for School Buses. It Didn’t Work

    These 40 Amazon Spring Sale Tech Deals Are Actually Good. We Checked the Price History (2026)

    These 40 Amazon Spring Sale Tech Deals Are Actually Good. We Checked the Price History (2026)

    What Is the Best Garmin Watch Right Now? (2026)

    What Is the Best Garmin Watch Right Now? (2026)

  • Entertainment
    Imax CEO Richard Gelfond Taking Temporary Medical Leave

    Imax CEO Richard Gelfond Taking Temporary Medical Leave

    ‘Tomb Raider’ Production ‘Paused’ After Sophie Turner Injured on Set

    ‘Tomb Raider’ Production ‘Paused’ After Sophie Turner Injured on Set

    ‘Maspalomas’ Wins Top Prize at Sonoma Film Festival

    ‘Maspalomas’ Wins Top Prize at Sonoma Film Festival

    Rob and Michele Reiner Remembered at Human Rights Campaign Gala

    Rob and Michele Reiner Remembered at Human Rights Campaign Gala

    Bruce Springsteen Performs ‘Streets of Minneapolis’ at No Kings Rally

    Bruce Springsteen Performs ‘Streets of Minneapolis’ at No Kings Rally

  • Travel
    This Seaside Town Is a Hidden Gem in California

    This Seaside Town Is a Hidden Gem in California

    Wimberley, Texas, Travel Guide

    Wimberley, Texas, Travel Guide

    15 Best Places to Visit in Georgia

    15 Best Places to Visit in Georgia

    Essential Guide to Beaufort, South Carolina

    Essential Guide to Beaufort, South Carolina

    REI Has Spring New Arrivals on Sale From $13

    REI Has Spring New Arrivals on Sale From $13

  • Lifestyle
    Ao Yes Shanghai Fall 2026 Collection

    Ao Yes Shanghai Fall 2026 Collection

    Tao Tokyo Fall 2026 Collection

    Tao Tokyo Fall 2026 Collection

    When Is the Best Time to Take Collagen?

    When Is the Best Time to Take Collagen?

    How to Plan Your Wedding According to Your Zodiac Sign

    How to Plan Your Wedding According to Your Zodiac Sign

    Oude Waag Shanghai Fall 2026 Collection

    Oude Waag Shanghai Fall 2026 Collection

  • Sports
    Giants’ Harbaugh open to possible Odell Beckham Jr. reunion

    Giants’ Harbaugh open to possible Odell Beckham Jr. reunion

    Hyo Joo Kim tops Nelly Korda again, wins LPGA’s Ford Champ.

    Hyo Joo Kim tops Nelly Korda again, wins LPGA’s Ford Champ.

    Caster Semenya calls out IOC chief over Olympic transgender ban

    Caster Semenya calls out IOC chief over Olympic transgender ban

    Arizona beats Purdue to make first Final Four since 2001

    Arizona beats Purdue to make first Final Four since 2001

    Men’s March Madness: Predictions, previews for Saturday’s Elite Eight

    Men’s March Madness: Predictions, previews for Saturday’s Elite Eight

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
61
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

The 54 Best Amazon New Year Luggage Deals

The 54 Best Amazon New Year Luggage Deals

January 2, 2026
Nanushka Pre-Fall 2025 Collection | Vogue

Nanushka Pre-Fall 2025 Collection | Vogue

December 11, 2024

Democrats’ Wary Response to Transgender Ruling Shows the Party’s Retreat

June 19, 2025

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years

Recent Posts

  • At least 70 killed, 30 wounded in Haiti gang attack, rights group says | Crime News
  • Michigan Synagogue Attack Was ‘Inspired by Hezbollah,’ Officials Say
  • Most Syrian refugees in Germany expected to return home in three years, Merz says
  • Gaza mother reunited with evacuated baby daughter
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?