Sign in

Karim El-Melhaoui

@karimscloud.bsky.social
207 followers 69 following 38 posts

Principal Security Architect & Partner at o3c.no, CloudSec Researcher, Microsoft Security MVP, CSA Norway Board Member

PostsRepliesMedia
Karim El-Melhaoui @karimscloud.bsky.social · 15/05/2025
My first bounty
010
Karim El-Melhaoui @karimscloud.bsky.social · 08/05/2025
Waiting… 🥲
120
Karim El-Melhaoui @karimscloud.bsky.social · 04/05/2025
I find it hard to believe that AWS charges me for having hourly data of costs in my AWS environment.
001
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025
.. You'd also have to first elevate yourself in order to remove another principal. It's interesting how a Global Admin has an invisible access to the Root scope.
000
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025
If you were to remove any of the users previously, it had to be done through the REST API, as the permission is inherited on the Tenant Root Group visible in the portal
100
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025
You can now see users that have triggered the Elevated Access toggle in Azure. A simple bypass is to immediately assign the principal the same permissions at the top level management group, Tenant Root Group (tenant ID) rather than the Root scope ("/"). I still think this is an important feature.
110
Karim El-Melhaoui @karimscloud.bsky.social · 01/05/2025
Finally read and implemented the AWS Delegated Management - @scottpiper.bsky.social’s article hits the nail on challebges - we built and maintained an internal API to access this information for automation purposes, which I would do again if it wasn’t for this feature www.wiz.io/blog/use-cas...
wiz.io
Use cases for Delegated Administrator for AWS Organizations | Wiz Blog
Learn about how AWS's recently released Delegated Administrator for AWS Organization can be used to solve common problems at your company and the issues you might run into with it.
022
Reposted by Karim El-Melhaoui
fwd:cloudsec @fwdcloudsec.org · 20/04/2025
We’re also happy to announce our Europe scholarship program. Through this initiative, we hope to give a limited number of students or those looking to make a career change a chance to attend the conference, through a complimentary ticket and a stipend to cover travel expenses..
fwdcloudsec.org
fwd:cloudsec | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
111
Reposted by Karim El-Melhaoui
fwd:cloudsec @fwdcloudsec.org · 20/04/2025
Ticket sales for fwd:cloudsec Europe 2025 goes live on April 22nd, first batch at 9 AM CET and a second batch at 7PM CET. Tickets are sold through Swoogo, link at fwdcloudsec.org/conference/e... ..
fwdcloudsec.org
fwd:cloudsec Europe 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
165
Reposted by Karim El-Melhaoui
Catalin Cimpanu @campuscodi.risky.biz · 19/04/2025
GitHub has released an unofficial tool to audit GitHub Actions Released after the Changed-Files debacle github.com/github/audit...
github.com
GitHub - github/audit-actions-workflow-runs: Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded
Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded - github/audit-actions-workflow-runs
0203
Karim El-Melhaoui @karimscloud.bsky.social · 18/04/2025
Cloudy at Fløtatind, Sunndal
010
Karim El-Melhaoui @karimscloud.bsky.social · 10/04/2025
or the common "hey how are you" to derail conversation before it has even started
110
Karim El-Melhaoui @karimscloud.bsky.social · 08/04/2025
Thanks for sharing! Had this discussion over a few beers with a TAM yesterday that had heard of similar cases
010
Karim El-Melhaoui @karimscloud.bsky.social · 08/04/2025
The only liberation we’ve experienced through the past week is the liberation of our savings
200
Karim El-Melhaoui @karimscloud.bsky.social · 07/04/2025
What happens if a lambda that puts an event to an S3 triggers on the same S3… I can’t afford to find out
100
Karim El-Melhaoui @karimscloud.bsky.social · 31/03/2025
Messed up an entire GCP org. trying to clean up inheritance using google_organization_iam_policy rather than binding. Will never know what random internal service account were assigned a hopefully not critical role.
020
Karim El-Melhaoui @karimscloud.bsky.social · 24/03/2025
It's happening again! We're looking for sponsors that will help support this years European conference🤝
000
Reposted by Karim El-Melhaoui
Audun Mo (he/him) @audunmo.dev · 20/03/2025
Is there any way to generate an SBOM that describes github actions and their transitive dependencies? Ref tj-actions. I feel like this should be a thing
011
Karim El-Melhaoui @karimscloud.bsky.social · 19/02/2025
Given this is the second time I look into an AWS Solutions product and find something interesting, with no AppSec background - I have a strong feeling there's more to be found..
000
Karim El-Melhaoui @karimscloud.bsky.social · 19/02/2025
Stumbled upon the Serverless Image Handler while looking into AWS Solutions: www.o3c.no/knowledge/ab...
o3c.no
Abusing AWS Serverless Image Handler
We recently discovered that the AWS solution ‘Dynamic Image Transformation for Amazon CloudFront’, previously known as ‘AWS Serverless Image Handler’, prior to version 6.2.6, contains a configuration ...
111
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025
I'll be in Singapore at that time, but for those lucky enough to make it - ENJOY and hope to see you next year or in Europe this Fall (TBA).
000
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025
Rather than maintaining a poorly written niche tool, we hope that the functionality will be adopted by more prevalent and widely adopted tools such as BloodHound or commercial offerings such as Wiz Code.
000
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025
Last week, we presented our latest research into Azure and OIDC where we also released our latest tool for mapping attack paths between Azure and GitHub www.o3c.no/knowledge/to...
o3c.no
Tool Release: Azure and OIDC - Code to Cloud
In conjunction with our talk at HackCon and the release of our latest tool in Research Release, are sharing this as a companion blog post.
120
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025
www.oreilly.com/radar/the-en...
oreilly.com
The End of Programming as We Know It
000
Reposted by Karim El-Melhaoui
Nick Frichette @frichetten.com · 05/02/2025
The CFP for the best cloud security conference on earth is now open! If you'd like your research to be presented alongside the cutting edge of the industry, this is your opportunity! fwdcloudsec.org/conference/n...
fwdcloudsec.org
CFP | NA 2025 | fwd:cloudsec
fwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security...
0197
Karim El-Melhaoui @karimscloud.bsky.social · 30/01/2025
I'll give this a go as well. Thanks for sharing!
000
Karim El-Melhaoui @karimscloud.bsky.social · 29/01/2025
Congrats, great addition to the Wiz team and now you have a reason to visit us in Norway
010
Karim El-Melhaoui @karimscloud.bsky.social · 29/01/2025
AWS just renamed the Serverless Image Handler solution to Dynamic Image Transformation for Amazon CloudFront aws.amazon.com/solutions/im...
aws.amazon.com
Dynamic Image Transformation for Amazon CloudFront | AWS Solutions | AWS Solutions Library
Dynamic Image Transformation for Amazon CloudFront (formerly Serverless Image Handler) enables real-time image processing through the global content delivery network (CDN) of Amazon CloudFront.
000
Karim El-Melhaoui @karimscloud.bsky.social · 01/01/2025
Starting the new year above the clouds
030
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
The full recording can be found here: media.ccc.de/v/38c3-wir-w.... There's an English audio track available. And the Spiegel article can be found here: www.spiegel.de/netzwelt/web...
media.ccc.de
Wir wissen wo dein Auto steht - Volksdaten von Volkswagen
Bewegungsdaten von 800.000 E-Autos sowie Kontaktinformationen zu den Besitzern standen ungeschützt im Netz. Sichtbar war, wer wann zu Hau...
020
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
.. They were able to access: - Specific Location data for any SEAT or Volkswagen car, as they forgot to sample it to a 10km radius. They sampled 10km for Audi, Skoda++ - Personal user information, such as home address, date of birth and email. - Any warnings the car may have had - A lot more..
100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
.. They continued to analyze the heapdump and used Strings to read data from the Headump, where they found a CLIENT_ID and CLIENT_SECRET. The CLIENT_ID and CLIENT_SECRET allows to authenticate as any user and to access user data directly to the application..
100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
.. It's unclear what they were able to do with the Access Keys, but the data accessed was exported from MongoDB, and 9,5TB of JSON data, so let's assume S3..
100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
.. enumerating the sub-domains using subfinder. Following the sub-domain enumeration, the endpoints were further enumerated using GoBuster. GoBuster revealed a Java Spring application with the Actuator endpoint enabled. The Actuator endpoint revealed an AWS Access Key and Heapdumps..
130
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024
Cariad, a subsidiary of Volkswagen Group recently had a data compromise in AWS. Unlike my initial instinct, this was not related to a Public or Unprotected bucket.. Looking further into the breach, published by the Chaos Computer Club (ccc.de) responsible for the disclosure it was discovered by..
154
Karim El-Melhaoui @karimscloud.bsky.social · 08/12/2024
Great writeup on Azure OpenAI Abuse by Matt Graber redcanary.com/blog/threat-...
redcanary.com
Artificial authentication: Monitoring Azure OpenAI abuse
Adversaries can compromise key material in Azure OpenAI to host malicious models, poison trained models, and steal intellectual property.
010
Karim El-Melhaoui @karimscloud.bsky.social · 02/12/2024
Will dedicate two weekends of AWS research before it’s Christmas holiday 🫡
010
Karim El-Melhaoui @karimscloud.bsky.social · 02/12/2024
First year I have FOMO for not attending #reinvent
110
Karim El-Melhaoui @karimscloud.bsky.social · 28/11/2024
Spent some time on AWS research tonight. I’m looking forward to interact with the new vulnerability disclosure program 🫡
030
Reposted by Karim El-Melhaoui
Cody Burkard @codyburkard.com · 25/11/2024
Are you an Azure Pentester looking for new lateral movement techniques? Take a look at my blog post about abusing Data Factory to steal secrets and tokens. Thanks @karimscloud.bsky.social for the inspiration to look into this. codyburkard.com/abusingselfh...
182
Karim El-Melhaoui @karimscloud.bsky.social · 22/11/2024
Found Mimikatz binaries in allowlisted folders a few months ago. Was certain the server was compromised but turned out to be left from a pentest years ago..
000
Karim El-Melhaoui @karimscloud.bsky.social · 21/11/2024
OIDC seems to be an underrated attack vector. If you can get hold of a GitHub token you’re more or less guaranteed to find a repo that triggers a privileged service account / role from a pull_request in a lot orgs.
000
Karim El-Melhaoui @karimscloud.bsky.social · 18/11/2024
Wrote some research on abusing Azure Data Factory www.o3c.no/knowledge/az... #cloudsecurity
o3c.no
Azure Data Factory - Abusing the Self-Hosted Integration Runtime
We recently discovered that Azure Data Factory has a Self-Hosted Integration Runtime (SHIR), where we can create jobs that use credentials provided through the Azure Portal.
040
Karim El-Melhaoui @karimscloud.bsky.social · 18/11/2024
Twitter has been dead for weeks, time to move on
080