Monday, May 11, 2026
City and Coffee
  • Home
  • World
    ‘Unacceptable’: What’s Iran’s peace proposal that Trump has rejected? | US-Israel war on Iran News

    ‘Unacceptable’: What’s Iran’s peace proposal that Trump has rejected? | US-Israel war on Iran News

    What next for Real Madrid after Barcelona’s La Liga and Clasico triumph? | Football News

    What next for Real Madrid after Barcelona’s La Liga and Clasico triumph? | Football News

    Passengers from Hantavirus-hit cruise begin disembarking ship | Health

    Passengers from Hantavirus-hit cruise begin disembarking ship | Health

    Satellite images show likely oil slick off Iran’s Kharg Island | Environment

    Satellite images show likely oil slick off Iran’s Kharg Island | Environment

    ‘A year of resistance’: Cuba’s private sector faces Trump’s oil blockade | Business and Economy

    ‘A year of resistance’: Cuba’s private sector faces Trump’s oil blockade | Business and Economy

  • US

    Dua Lipa Sues Samsung Over Use of Her Image on TV Packaging

    6 Bodies Found in a Boxcar in Texas, Officials Say

    Kristin Smart Search Ends Without Recovery of Remains at California Property

    The G.O.P. Rush To Break Up Majority-Black Districts

    The G.O.P. Rush To Break Up Majority-Black Districts

    Frontier Jet Hits Person on Runway During Takeoff at Denver Airport

  • Europe
    US and French nationals test positive for hantavirus after leaving ship

    US and French nationals test positive for hantavirus after leaving ship

    Why Eurovision's fallout over Israel may change the competition forever

    Why Eurovision's fallout over Israel may change the competition forever

    Spain starts evacuating virus-hit cruise ship in Tenerife

    Spain starts evacuating virus-hit cruise ship in Tenerife

    WHO chief reassures Tenerife residents ahead of arrival of virus-hit cruise ship

    WHO chief reassures Tenerife residents ahead of arrival of virus-hit cruise ship

    Putin denounces Nato at scaled back Victory Day parade

    Putin denounces Nato at scaled back Victory Day parade

  • MENA
    Ailing Iranian Nobel laureate given bail and hospital transfer

    Ailing Iranian Nobel laureate given bail and hospital transfer

    BBC speaks with civilians inside Iran struggling with impact of war

    BBC speaks with civilians inside Iran struggling with impact of war

    Iran demands guarantees for World Cup participation

    Iran demands guarantees for World Cup participation

    Lebanon says Israeli strikes killed 39

    Lebanon says Israeli strikes killed 39

    Iran considering US proposal as Trump says war will be 'over quickly'

    Iran considering US proposal as Trump says war will be 'over quickly'

  • APAC
    Philippine VP Sara Duterte impeached for a second time

    Philippine VP Sara Duterte impeached for a second time

    Police find body believed to be of fugitive Australian shooter

    Police find body believed to be of fugitive Australian shooter

    Indian model's understated Met Gala debut revives debate on cultural representation

    Indian model's understated Met Gala debut revives debate on cultural representation

    Buddhist monk arrested over alleged rape of teen in Sri Lanka

    Buddhist monk arrested over alleged rape of teen in Sri Lanka

    Japanese council votes to remove unconscious mayor

    Japanese council votes to remove unconscious mayor

  • Tech
    Testing for ‘Bad Cholesterol’ Doesn’t Tell the Whole Story

    Testing for ‘Bad Cholesterol’ Doesn’t Tell the Whole Story

    CUDA Proves Nvidia Is a Software Company

    CUDA Proves Nvidia Is a Software Company

    Could Contact-Tracing Apps Help With the Hantavirus? Not Really

    Could Contact-Tracing Apps Help With the Hantavirus? Not Really

    Do City Delivery Drones Make Sense? No One Knows, but They’re Flying Over NYC

    Do City Delivery Drones Make Sense? No One Knows, but They’re Flying Over NYC

    Best Live-Captioning Smart Glasses (2026), WIRED tested

    Best Live-Captioning Smart Glasses (2026), WIRED tested

  • Entertainment
    ‘The Rings of Power’ Season 3 Sets Fall Release Date

    ‘The Rings of Power’ Season 3 Sets Fall Release Date

    Producer Lorenzo Gangarossa Joins Canal + Group-owned Lucky Red

    Producer Lorenzo Gangarossa Joins Canal + Group-owned Lucky Red

    Return of the Jedi’ Actor Was 82

    Return of the Jedi’ Actor Was 82

    The Secret Agent,’ “The Eternaut’ Sweep Premios Platino

    The Secret Agent,’ “The Eternaut’ Sweep Premios Platino

    ‘SNL U.K.’ Weekend Update Takes Aim at Katy Perry’s ‘Stupid Moron’ Mask

    ‘SNL U.K.’ Weekend Update Takes Aim at Katy Perry’s ‘Stupid Moron’ Mask

  • Travel
    This Seaside Town Is a Hidden Gem in California

    This Seaside Town Is a Hidden Gem in California

    Wimberley, Texas, Travel Guide

    Wimberley, Texas, Travel Guide

    15 Best Places to Visit in Georgia

    15 Best Places to Visit in Georgia

    Essential Guide to Beaufort, South Carolina

    Essential Guide to Beaufort, South Carolina

    REI Has Spring New Arrivals on Sale From $13

    REI Has Spring New Arrivals on Sale From $13

  • Lifestyle
    Rachel Antonoff Spring 2026 Ready-to-Wear Collection

    Rachel Antonoff Spring 2026 Ready-to-Wear Collection

    Beare Park Australia Resort 2027

    Beare Park Australia Resort 2027

    Rihanna’s New Tattoo Was ‘Designed by Her Babies’

    Rihanna’s New Tattoo Was ‘Designed by Her Babies’

    This New Cookbook by the Founder of Ghia Will Transport You Straight to a Mediterranean Summer

    This New Cookbook by the Founder of Ghia Will Transport You Straight to a Mediterranean Summer

    This Stylist Bride’s Menorca Wedding Began in a Historic Limestone Quarry and Ended in a Secret Nightclub

    This Stylist Bride’s Menorca Wedding Began in a Historic Limestone Quarry and Ended in a Secret Nightclub

  • Sports
    World Cup 2026: Dick Advocaat open to return as Curacao boss resigns

    World Cup 2026: Dick Advocaat open to return as Curacao boss resigns

    Rashford goal helps Barca beat Real Madrid to lift title

    Rashford goal helps Barca beat Real Madrid to lift title

    Italian Open: Iga Swiatek sets up Naomi Osaka meeting

    Italian Open: Iga Swiatek sets up Naomi Osaka meeting

    Women’s Six Nations 2026: Ireland 33-12 Wales: ‘Ireland ‘still hungry to get better’ – Bemand

    Women’s Six Nations 2026: Ireland 33-12 Wales: ‘Ireland ‘still hungry to get better’ – Bemand

    Women’s Six Nations 2026: Ireland 33-12 Wales: Ireland overcome Wales Ireland overcome Wales for hard-fought home win

    Women’s Six Nations 2026: Ireland 33-12 Wales: Ireland overcome Wales Ireland overcome Wales for hard-fought home win

  • Blogs
No Result
View All Result
City and Coffee
No Result
View All Result
Home Tech

An AWS Configuration Issue Could Expose Thousands of Web Apps

content@helloomylife.com by content@helloomylife.com
August 20, 2024
in Tech
0
An AWS Configuration Issue Could Expose Thousands of Web Apps
0
SHARES
64
VIEWS
Share on FacebookShare on Twitter


A vulnerability associated to Amazon Net Service’s traffic-routing service generally known as Utility Load Balancer may have been exploited by an attacker to bypass entry controls and compromise internet purposes, in accordance with new analysis. The flaw stems from a buyer implementation concern, which means it is not brought on by a software program bug. As an alternative, the publicity was launched by the way in which AWS customers arrange authentication with Utility Load Balancer.

Implementation points are a vital part of cloud safety in the identical means that the contents of an armored protected aren’t protected if the door is left ajar. Researchers from the safety agency Miggo found that, relying on how Utility Load Balancer authentication was arrange, an attacker may doubtlessly manipulate its handoff to a third-party company authentication service to entry the goal internet software and examine or exfiltrate knowledge.

The researchers say that publicly reachable internet purposes, they’ve recognized greater than 15,000 that seem to have susceptible configurations. AWS disputes this estimate, although, and says that “a small fraction of a p.c of AWS prospects have purposes doubtlessly misconfigured on this means, considerably fewer than the researchers’ estimate.” The corporate additionally says that it has contacted every buyer on its shorter checklist to suggest a safer implementation. AWS doesn’t have entry or visibility into its purchasers’ cloud environments, although, so any actual quantity is simply an estimate.

The Miggo researchers say they got here throughout the issue whereas working with a shopper. This “was found in real-life manufacturing environments,” Miggo CEO Daniel Shechter says. “We noticed a bizarre habits in a buyer system—the validation course of appeared prefer it was solely being executed partially, like there was one thing lacking. This actually reveals how deep the interdependencies go between the shopper and the seller.”

To use the implementation concern, an attacker would arrange an AWS account and an Utility Load Balancer, after which signal their very own authentication token as regular. Subsequent, the attacker would make configuration modifications so it will seem their goal’s authentication service issued the token. Then the attacker would have AWS signal the token as if it had legitimately originated from the goal’s system and use it to entry the goal software. The assault should particularly goal a misconfigured software that’s publicly accessible or that the attacker already has entry to, however would permit them to escalate their privileges within the system.

Amazon Net Providers says that the corporate doesn’t view token forging as a vulnerability in Utility Load Balancer as a result of it’s primarily an anticipated end result of selecting to configure authentication in a selected means. However after the Miggo researchers first disclosed their findings to AWS originally of April, the corporate made two documentation changes geared at updating their implementation suggestions for Utility Load Balancer authentication. One, from Might 1, included steering to add validation earlier than Utility Load Balancer will signal tokens. And on July 19, the corporate additionally added an express suggestion that customers set their techniques to obtain visitors from solely their very own Utility Load Balancer using a feature called “security groups.”



Source link

Tags: AppsAWSConfigurationExposeIssueThousandsWeb
Previous Post

Taylor Swift Debuts ‘I Can Do It With A Broken Heart’ Music Video

Next Post

Everest’s Sherpas fear their homeland is at risk of washing away

Next Post
Everest’s Sherpas fear their homeland is at risk of washing away

Everest's Sherpas fear their homeland is at risk of washing away

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

ADVERTISEMENT

Premium Content

The Orlando Neighborhood With More Michelin-recommended Restaurants Than Anywhere Else in Town

The Orlando Neighborhood With More Michelin-recommended Restaurants Than Anywhere Else in Town

September 9, 2025
SC103 Fall 2026 Ready-to-Wear Collection

SC103 Fall 2026 Ready-to-Wear Collection

February 13, 2026

2 Children Are Dead and 2 Are in Critical Condition in Texas Shooting

October 4, 2025

Browse by Category

  • APAC
  • Entertainment
  • Europe
  • Lifestyle
  • MENA
  • Sports
  • Tech
  • Travel
  • US
  • World

Browse by Tags

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years
City and Coffee

We provide the most reliable and up-to-date news from around the globe. Stay informed with our unbiased coverage of the latest events, trends, and stories. Trust us as your daily source for breaking news and insightful analysis

Browse by Tag

Amazon attack attacks ceasefire China City Collection Conflict Day dead deal Deals Donald Fall Football Gaza Hamas India Iran Israel Israeli killed Live Man News ReadytoWear Review Russia Russian South Spring strike strikes talks Top travel Trump Trumps U.S Ukraine war Week Win World Years

Recent Posts

  • Philippine VP Sara Duterte impeached for a second time
  • Testing for ‘Bad Cholesterol’ Doesn’t Tell the Whole Story
  • ‘The Rings of Power’ Season 3 Sets Fall Release Date
  • Rachel Antonoff Spring 2026 Ready-to-Wear Collection
No Result
View All Result
  • Home
  • World
  • US
  • Europe
  • MENA
  • APAC
  • Tech
  • Entertainment
  • Travel
  • Lifestyle
  • Sports
  • Blogs

© 2024 All Rights Reserved | cityandcoffee.com

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?