Friday, May 29, 2026
City and Coffee
  • Home
  • World
    Iran war live: Trump threatens Tehran; Saudi, UAE report drone attacks

    Iran war live: Trump threatens Tehran; Saudi, UAE report drone attacks

    How will Izz al-Din al-Haddad assassination impact Hamas’s Gaza operations? | Drone Strikes News

    How will Izz al-Din al-Haddad assassination impact Hamas’s Gaza operations? | Drone Strikes News

    Tunisians rally amid economic crisis and political arrests | Protests

    Tunisians rally amid economic crisis and political arrests | Protests

    Zimbabwe’s diaspora reshapes real estate and farming investment trends | Features

    Zimbabwe’s diaspora reshapes real estate and farming investment trends | Features

    Iran war live: Lebanon, Israel extend truce; Tehran ready for more US talks | US-Israel war on Iran News

    Iran war live: Lebanon, Israel extend truce; Tehran ready for more US talks | US-Israel war on Iran News

  • US

    Eager for Arms Deal, Taiwan Stresses Need for U.S. Support

    A Young Socialist Mayor, Starbucks and the Tension Over Soaking the Rich

    The Fight for Voting Rights Returns to Selma

    What to Watch in Saturday’s Republican Senate Primary in Louisiana

    Catholic Clergy Can Minister Within Illinois ICE Facility After Legal Agreement

  • Europe
    Eurovision winner Dara arrives to screaming fans in Bulgaria

    Eurovision winner Dara arrives to screaming fans in Bulgaria

    Swatch shuts stores after crowds queue for new watch

    Swatch shuts stores after crowds queue for new watch

    Man drives car into pedestrians in Italy, injuring eight

    Man drives car into pedestrians in Italy, injuring eight

    AI vigilante trap snares alleged paedophile ex-teacher in France

    AI vigilante trap snares alleged paedophile ex-teacher in France

    Switzerland finally to open secret files on Nazis’ Auschwitz ‘Angel of Death’

    Switzerland finally to open secret files on Nazis’ Auschwitz ‘Angel of Death’

  • MENA
    Political executions surge in Iran

    Political executions surge in Iran

    Hezbollah drone strike videos show evolving tactics against Israel

    Hezbollah drone strike videos show evolving tactics against Israel

    US charges Iraqi with plots to target Jews in cities from London to LA

    US charges Iraqi with plots to target Jews in cities from London to LA

    Hamas confirms top commander killed in Israeli air strike

    Hamas confirms top commander killed in Israeli air strike

    Israel and Lebanon agree to extend ceasefire, US state department says

    Israel and Lebanon agree to extend ceasefire, US state department says

  • APAC
    Freight train and bus crash kills at least eight in Bangkok

    Freight train and bus crash kills at least eight in Bangkok

    Why foreign tourists are turning away from India’s party capital

    Why foreign tourists are turning away from India’s party capital

    Taiwan reaffirms independence despite Trump warning

    Taiwan reaffirms independence despite Trump warning

    Trump warns Taiwan against declaring independence, hours after summit with China's Xi

    Trump warns Taiwan against declaring independence, hours after summit with China's Xi

    US and China conclude ‘very successful’ talks but few deals confirmed

    US and China conclude ‘very successful’ talks but few deals confirmed

  • Tech
    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

    Oto Smart Sprinkler Review (2026): Solar-Powered and Simple to Use

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    The 6 Best Grills and Smokers of 2026: Smart, Portable, Pellet

    Old Oil and Gas Wells Could Find Second Life Producing Clean Energy

    Old Oil and Gas Wells Could Find Second Life Producing Clean Energy

    After Struggling With EVs, US Automakers Pivot to Energy

    After Struggling With EVs, US Automakers Pivot to Energy

    The Best Outdoor Deals From the REI Anniversary Sale 2026

    The Best Outdoor Deals From the REI Anniversary Sale 2026

  • Entertainment
    Michael Fassbender, Alicia Vikander Gets Cannes Ovation for ‘Hope’

    Michael Fassbender, Alicia Vikander Gets Cannes Ovation for ‘Hope’

    Raya Martin’s Horror Thriller ‘Obosen’ Lands at Rein Entertainment

    Raya Martin’s Horror Thriller ‘Obosen’ Lands at Rein Entertainment

    Harry Styles Electrifies Amsterdam With’Together’ Tour: Concert Review

    Harry Styles Electrifies Amsterdam With’Together’ Tour: Concert Review

    Olga Kurylenko Leads Action Thriller ‘The Cop and the Assassin’

    Olga Kurylenko Leads Action Thriller ‘The Cop and the Assassin’

    ‘Gentle Monster’ Review: A Harrowing End-Of-Family Drama

    ‘Gentle Monster’ Review: A Harrowing End-Of-Family Drama

  • Travel
    This Seaside Town Is a Hidden Gem in California

    This Seaside Town Is a Hidden Gem in California

    Wimberley, Texas, Travel Guide

    Wimberley, Texas, Travel Guide

    15 Best Places to Visit in Georgia

    15 Best Places to Visit in Georgia

    Essential Guide to Beaufort, South Carolina

    Essential Guide to Beaufort, South Carolina

    REI Has Spring New Arrivals on Sale From $13

    REI Has Spring New Arrivals on Sale From $13

  • Lifestyle
    Gucci Resort 2027 Collection | Vogue

    Gucci Resort 2027 Collection | Vogue

    All the Fashions From the 2026 Cannes Film Festival Red Carpet

    All the Fashions From the 2026 Cannes Film Festival Red Carpet

    Discover the Best Dresses for Every May Occasion

    Discover the Best Dresses for Every May Occasion

    Pratt Institute Fall 2026 Ready-to-Wear Collection

    Pratt Institute Fall 2026 Ready-to-Wear Collection

    LVMH to Sell Marc Jacobs to WHP Global

    LVMH to Sell Marc Jacobs to WHP Global

  • Sports
    Ronnie O’Sullivan beats Luca Brecel to win Snooker 900 title

    Ronnie O’Sullivan beats Luca Brecel to win Snooker 900 title

    Rangers to pursue Moore return – gossip

    Rangers to pursue Moore return – gossip

    Italian Open: Elina Svitolina stuns Coco Gauff to win thrilling final

    Italian Open: Elina Svitolina stuns Coco Gauff to win thrilling final

    Celtic’s Maeda reveals ambition to play in England – gossip

    Celtic’s Maeda reveals ambition to play in England – gossip

    World Cup 2026: Haiti squad includes Wilson Isidor and Jean-Ricner Bellegarde

    World Cup 2026: Haiti squad includes Wilson Isidor and Jean-Ricner Bellegarde

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
65
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

US tourist arrested after visit to restricted North Sentinel island

US tourist arrested after visit to restricted North Sentinel island

April 3, 2025
Earth’ Star David Rysdahl on Arthur’s Distrust in Prodigy

Earth’ Star David Rysdahl on Arthur’s Distrust in Prodigy

August 27, 2025
US-South Korea nuclear submarine deal: What does it mean?

US-South Korea nuclear submarine deal: What does it mean?

November 16, 2025

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years

Recent Posts

  • Iran war live: Trump threatens Tehran; Saudi, UAE report drone attacks
  • Eager for Arms Deal, Taiwan Stresses Need for U.S. Support
  • Eurovision winner Dara arrives to screaming fans in Bulgaria
  • Political executions surge in Iran
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?