Tuesday, April 21, 2026
City and Coffee
  • Home
  • World
    EU credibility is on the line over Israel, says Spanish foreign minister | Russia-Ukraine war

    EU credibility is on the line over Israel, says Spanish foreign minister | Russia-Ukraine war

    Six women win 2026 Goldman prize, world’s top environmental award | Environment News

    Six women win 2026 Goldman prize, world’s top environmental award | Environment News

    What we know about the US capture of Iranian vessel near Hormuz | US-Israel war on Iran

    What we know about the US capture of Iranian vessel near Hormuz | US-Israel war on Iran

    What’s behind the US army’s decision to raise enlistment age to 42? | Military News

    What’s behind the US army’s decision to raise enlistment age to 42? | Military News

    Russia confirms high-level talks on Ukraine in Saudi Arabia | News

    Trump says US negotiators to head to Pakistan for Iran ceasefire talks | News

  • US

    A Rocky, Snow-Barren Ski Season Concludes in Colorado

    ‘Immediate Results’ vs. ‘The Long Game’: the U.S. and Iran Face Off

    From Pulpit to Pews, Trump and Pope Are on the Minds of Catholics

    8 Children Killed in Domestic Mass Shooting in Shreveport, Louisiana, Police Say

    Syrian Billionaires Needed a Favor in Washington. They Invoked the Trump Name.

  • Europe
    French Open: Carlos Alcaraz says test on wrist injury ‘crucial’ for hopes of defending title

    French Open: Carlos Alcaraz says test on wrist injury ‘crucial’ for hopes of defending title

    Musk snubs interview summons by French prosecutors amid X probe

    Musk snubs interview summons by French prosecutors amid X probe

    Ukraine police chief resigns after officers allegedly fled deadly shooting

    Ukraine police chief resigns after officers allegedly fled deadly shooting

    Rumen Radev looks set to win Bulgarian Parliamentary election

    Rumen Radev looks set to win Bulgarian Parliamentary election

    Rat poison found in HiPP baby food jar in Austria, police say

    Rat poison found in HiPP baby food jar in Austria, police say

  • MENA
    Popemobile child clinic yet to reach Gaza one year after Francis's death

    Popemobile child clinic yet to reach Gaza one year after Francis's death

    Outrage over Israeli soldier’s vandalism of Jesus statue in Lebanon

    Outrage over Israeli soldier’s vandalism of Jesus statue in Lebanon

    US releases video of forces seizing Iranian ship

    US releases video of forces seizing Iranian ship

    US intercepts and seizes Iranian-flagged cargo ship, Trump says

    US intercepts and seizes Iranian-flagged cargo ship, Trump says

    French peacekeeper killed in southern Lebanon

    French peacekeeper killed in southern Lebanon

  • APAC
    Japan loosens arms export rules in break from post-WW2 pacifism

    Japan loosens arms export rules in break from post-WW2 pacifism

    Japan on high alert for 'huge' second quake after issuing tsunami warning

    Japan on high alert for 'huge' second quake after issuing tsunami warning

    New Zealand declares state of emergency in Wellington as floods hit

    New Zealand declares state of emergency in Wellington as floods hit

    Drone footage shows huge Malaysian coastal village fire

    Drone footage shows huge Malaysian coastal village fire

    The South Korean authors rising above a tide of hate to become bestsellers

    The South Korean authors rising above a tide of hate to become bestsellers

  • Tech
    They Built a Legendary Privacy Tool. Now They’re Sworn Enemies

    They Built a Legendary Privacy Tool. Now They’re Sworn Enemies

    Apple CEO Tim Cook Is Stepping Down

    Apple CEO Tim Cook Is Stepping Down

    The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad

    The Weird, Twisting Tale of How China Spied on Alysa Liu and Her Dad

    Best Meta Glasses (2026): Ray-Ban, Oakley, AR

    Best Meta Glasses (2026): Ray-Ban, Oakley, AR

    Our Favorite Apple Watch Has Never Been Less Expensive

    Our Favorite Apple Watch Has Never Been Less Expensive

  • Entertainment
    Karlovy Vary to Celebrate 80 Years Since First Festival, 60th Edition

    Karlovy Vary to Celebrate 80 Years Since First Festival, 60th Edition

    Marvel Visual Director Andy Park Out After 16 Years Amid Disney Layoffs

    Marvel Visual Director Andy Park Out After 16 Years Amid Disney Layoffs

    ‘Days of Our Lives,’ ‘Melrose Place’ Actor Was 57

    ‘Days of Our Lives,’ ‘Melrose Place’ Actor Was 57

    Ella Langley’s ‘Dandelion’ Debuts at No. 1 on Billboard Album Chart

    Ella Langley’s ‘Dandelion’ Debuts at No. 1 on Billboard Album Chart

    Justin Bieber Serenades Billie Eilish, Duets With SZA at Coachella

    Justin Bieber Serenades Billie Eilish, Duets With SZA at Coachella

  • Travel
    This Seaside Town Is a Hidden Gem in California

    This Seaside Town Is a Hidden Gem in California

    Wimberley, Texas, Travel Guide

    Wimberley, Texas, Travel Guide

    15 Best Places to Visit in Georgia

    15 Best Places to Visit in Georgia

    Essential Guide to Beaufort, South Carolina

    Essential Guide to Beaufort, South Carolina

    REI Has Spring New Arrivals on Sale From $13

    REI Has Spring New Arrivals on Sale From $13

  • Lifestyle
    AI Is Everywhere. Fashion Photographers Are Being Forced to Adapt

    AI Is Everywhere. Fashion Photographers Are Being Forced to Adapt

    The Snack Tin is Here To Save You From the Afternoon Slump

    The Snack Tin is Here To Save You From the Afternoon Slump

    60 Thoughts I Had About Season 3, Episode 2 of ‘Euphoria’

    60 Thoughts I Had About Season 3, Episode 2 of ‘Euphoria’

    Zendaya Delivers One More Cheeky Bridal Serve for Her ‘The Drama’ Tour

    Zendaya Delivers One More Cheeky Bridal Serve for Her ‘The Drama’ Tour

    Dior Fashioned Ethel Cain a “Haunted” Dress for Coachella

    Dior Fashioned Ethel Cain a “Haunted” Dress for Coachella

  • Sports
    Bayern deserve to be celebrated after Bundesliga title win

    Bayern deserve to be celebrated after Bundesliga title win

    2026 NBA playoffs: Western Conference first-round takeaways

    2026 NBA playoffs: Western Conference first-round takeaways

    Dexter Lawrence trade: Bengals, Giants, NFL draft takeaways

    Dexter Lawrence trade: Bengals, Giants, NFL draft takeaways

    2026 NFL draft: Louis Riddick’s favorite prospects, sleepers

    2026 NFL draft: Louis Riddick’s favorite prospects, sleepers

    NBA offseason: Draft, free agency, trade targets for eliminated teams

    NBA offseason: Draft, free agency, trade targets for eliminated teams

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
63
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

Saatva Memory Foam Hybrid Mattress Review: Going for Gold and Good Sleep

Saatva Memory Foam Hybrid Mattress Review: Going for Gold and Good Sleep

February 16, 2026
US Postal Service stops accepting parcels from China

US Postal Service stops accepting parcels from China

February 5, 2025
Monique Lhuillier Fall 2026 Ready-to-Wear Collection

Monique Lhuillier Fall 2026 Ready-to-Wear Collection

January 21, 2026

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli IsraelPalestine killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years

Recent Posts

  • EU credibility is on the line over Israel, says Spanish foreign minister | Russia-Ukraine war
  • A Rocky, Snow-Barren Ski Season Concludes in Colorado
  • French Open: Carlos Alcaraz says test on wrist injury ‘crucial’ for hopes of defending title
  • Popemobile child clinic yet to reach Gaza one year after Francis's death
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?