InInfoSec Write-upsbyPawel Rzepa·Dec 1, 2022pentesting.cloud part 2: “Is there an echo in here?” AWS CTF walkthroughIn this blog post I’m going to show you a technique of uncovering a CloudFormation values protected by the NoEcho property. In other words…
InInfoSec Write-upsbyPawel Rzepa·Nov 3, 2022pentesting.cloud part 1: “Open To The Public” CTF walkthroughRecently I have a very good time playing the pentesting.cloud CTF and in this blog post I want to start a new walkthrough series of IMHO…A response icon1A response icon1
InTowards AWSbyPawel Rzepa·Oct 24, 2022AWS security assessment: what scanners are missing and how threat modeling may help you?There are many tools available today that are designed to automate security checks. For example, here’s a good list of open-source AWS…A response icon2A response icon2
InInside the Tech by SoftServebyPawel Rzepa·Aug 26, 2021AWS privilege escalation: exploring odd features of the Trust PolicyIn this article I’ll present 2 situations when an adversary can abuse Trust Policy access model and assume a role without (any) permissionsA response icon2A response icon2
InTowards AWSbyPawel Rzepa·Jul 7, 2021How to defend against DNS exfiltration in AWS?TL;DRA response icon1A response icon1
Pawel Rzepa·Apr 19, 2021AWS and HackerOne CTF write-upRecently, @d0nutpr built an AWS-based CTF on HackerOne platform. The CTF was time-limited (available just for a week⏳), so I guess not all…
Pawel Rzepa·Jan 3, 2021How can you benefit by sharing your knowledge?Ending of the year is often good time to do some summary of your current achievements and future goals. My review of 2020 inspired me to…
InThe StartupbyPawel Rzepa·Nov 19, 2020AWS Access Keys Leak in GitHub Repository and Some Improvements in Amazon ReactionAWS access keys leak via public code repository is quite known security problem. So common, that popular version control systems offer for…A response icon1A response icon1
InSecuRingbyPawel Rzepa·Mar 5, 2020Serverless (in)securityserverless opens up a number of benefits for us, but we can’t forget about its threats. Even if you “believe” in security of your code, you
Pawel Rzepa·Nov 5, 2019Passing the AWS Certified Security Speciality examRecently I’ve passed the “AWS Certified Security — Speciality” exam, so I think that’s the best proof that my preparation process was good…A response icon6A response icon6