Karim El-Melhaoui @karimscloud.bsky.social · 04/05/2025I find it hard to believe that AWS charges me for having hourly data of costs in my AWS environment. 001
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025.. You'd also have to first elevate yourself in order to remove another principal. It's interesting how a Global Admin has an invisible access to the Root scope. 000
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025If you were to remove any of the users previously, it had to be done through the REST API, as the permission is inherited on the Tenant Root Group visible in the portal 100
Karim El-Melhaoui @karimscloud.bsky.social · 03/05/2025You can now see users that have triggered the Elevated Access toggle in Azure. A simple bypass is to immediately assign the principal the same permissions at the top level management group, Tenant Root Group (tenant ID) rather than the Root scope ("/"). I still think this is an important feature. 110
Karim El-Melhaoui @karimscloud.bsky.social · 01/05/2025Finally read and implemented the AWS Delegated Management - @scottpiper.bsky.social’s article hits the nail on challebges - we built and maintained an internal API to access this information for automation purposes, which I would do again if it wasn’t for this feature www.wiz.io/blog/use-cas...wiz.ioUse cases for Delegated Administrator for AWS Organizations | Wiz BlogLearn about how AWS's recently released Delegated Administrator for AWS Organization can be used to solve common problems at your company and the issues you might run into with it. 022
Reposted by Karim El-Melhaouifwd:cloudsec @fwdcloudsec.org · 20/04/2025We’re also happy to announce our Europe scholarship program. Through this initiative, we hope to give a limited number of students or those looking to make a career change a chance to attend the conference, through a complimentary ticket and a stipend to cover travel expenses..fwdcloudsec.orgfwd:cloudsec | fwd:cloudsecfwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security... 111
Reposted by Karim El-Melhaouifwd:cloudsec @fwdcloudsec.org · 20/04/2025Ticket sales for fwd:cloudsec Europe 2025 goes live on April 22nd, first batch at 9 AM CET and a second batch at 7PM CET. Tickets are sold through Swoogo, link at fwdcloudsec.org/conference/e... ..fwdcloudsec.orgfwd:cloudsec Europe 2025 | fwd:cloudsecfwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security... 165
Reposted by Karim El-MelhaouiCatalin Cimpanu @campuscodi.risky.biz · 19/04/2025GitHub has released an unofficial tool to audit GitHub Actions Released after the Changed-Files debacle github.com/github/audit...github.comGitHub - github/audit-actions-workflow-runs: Audit your GitHub Actions workflow runs to see exactly which Actions were downloadedAudit your GitHub Actions workflow runs to see exactly which Actions were downloaded - github/audit-actions-workflow-runs 0203
Karim El-Melhaoui @karimscloud.bsky.social · 10/04/2025or the common "hey how are you" to derail conversation before it has even started 110
Karim El-Melhaoui @karimscloud.bsky.social · 08/04/2025Thanks for sharing! Had this discussion over a few beers with a TAM yesterday that had heard of similar cases 010
Karim El-Melhaoui @karimscloud.bsky.social · 08/04/2025The only liberation we’ve experienced through the past week is the liberation of our savings 200
Karim El-Melhaoui @karimscloud.bsky.social · 07/04/2025What happens if a lambda that puts an event to an S3 triggers on the same S3… I can’t afford to find out 100
Karim El-Melhaoui @karimscloud.bsky.social · 31/03/2025Messed up an entire GCP org. trying to clean up inheritance using google_organization_iam_policy rather than binding. Will never know what random internal service account were assigned a hopefully not critical role. 020
Karim El-Melhaoui @karimscloud.bsky.social · 24/03/2025It's happening again! We're looking for sponsors that will help support this years European conference🤝 000
Reposted by Karim El-MelhaouiAudun Mo (he/him) @audunmo.dev · 20/03/2025Is there any way to generate an SBOM that describes github actions and their transitive dependencies? Ref tj-actions. I feel like this should be a thing 011
Karim El-Melhaoui @karimscloud.bsky.social · 19/02/2025Given this is the second time I look into an AWS Solutions product and find something interesting, with no AppSec background - I have a strong feeling there's more to be found.. 000
Karim El-Melhaoui @karimscloud.bsky.social · 19/02/2025Stumbled upon the Serverless Image Handler while looking into AWS Solutions: www.o3c.no/knowledge/ab...o3c.noAbusing AWS Serverless Image HandlerWe recently discovered that the AWS solution ‘Dynamic Image Transformation for Amazon CloudFront’, previously known as ‘AWS Serverless Image Handler’, prior to version 6.2.6, contains a configuration ... 111
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025I'll be in Singapore at that time, but for those lucky enough to make it - ENJOY and hope to see you next year or in Europe this Fall (TBA). 000
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025Rather than maintaining a poorly written niche tool, we hope that the functionality will be adopted by more prevalent and widely adopted tools such as BloodHound or commercial offerings such as Wiz Code. 000
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025Last week, we presented our latest research into Azure and OIDC where we also released our latest tool for mapping attack paths between Azure and GitHub www.o3c.no/knowledge/to...o3c.noTool Release: Azure and OIDC - Code to CloudIn conjunction with our talk at HackCon and the release of our latest tool in Research Release, are sharing this as a companion blog post. 120
Karim El-Melhaoui @karimscloud.bsky.social · 18/02/2025www.oreilly.com/radar/the-en...oreilly.comThe End of Programming as We Know It 000
Reposted by Karim El-MelhaouiNick Frichette @frichetten.com · 05/02/2025The CFP for the best cloud security conference on earth is now open! If you'd like your research to be presented alongside the cutting edge of the industry, this is your opportunity! fwdcloudsec.org/conference/n...fwdcloudsec.orgCFP | NA 2025 | fwd:cloudsecfwd:cloudsec is a non-profit conference on cloud security. At this conference you can expect discussions about all the major cloud platforms, both attack and defense research, limitations of security... 0197
Karim El-Melhaoui @karimscloud.bsky.social · 30/01/2025I'll give this a go as well. Thanks for sharing! 000
Karim El-Melhaoui @karimscloud.bsky.social · 29/01/2025Congrats, great addition to the Wiz team and now you have a reason to visit us in Norway 010
Karim El-Melhaoui @karimscloud.bsky.social · 29/01/2025AWS just renamed the Serverless Image Handler solution to Dynamic Image Transformation for Amazon CloudFront aws.amazon.com/solutions/im...aws.amazon.comDynamic Image Transformation for Amazon CloudFront | AWS Solutions | AWS Solutions LibraryDynamic Image Transformation for Amazon CloudFront (formerly Serverless Image Handler) enables real-time image processing through the global content delivery network (CDN) of Amazon CloudFront. 000
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024The full recording can be found here: media.ccc.de/v/38c3-wir-w.... There's an English audio track available. And the Spiegel article can be found here: www.spiegel.de/netzwelt/web...media.ccc.deWir wissen wo dein Auto steht - Volksdaten von VolkswagenBewegungsdaten von 800.000 E-Autos sowie Kontaktinformationen zu den Besitzern standen ungeschützt im Netz. Sichtbar war, wer wann zu Hau... 020
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024.. They were able to access: - Specific Location data for any SEAT or Volkswagen car, as they forgot to sample it to a 10km radius. They sampled 10km for Audi, Skoda++ - Personal user information, such as home address, date of birth and email. - Any warnings the car may have had - A lot more.. 100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024.. They continued to analyze the heapdump and used Strings to read data from the Headump, where they found a CLIENT_ID and CLIENT_SECRET. The CLIENT_ID and CLIENT_SECRET allows to authenticate as any user and to access user data directly to the application.. 100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024.. It's unclear what they were able to do with the Access Keys, but the data accessed was exported from MongoDB, and 9,5TB of JSON data, so let's assume S3.. 100
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024.. enumerating the sub-domains using subfinder. Following the sub-domain enumeration, the endpoints were further enumerated using GoBuster. GoBuster revealed a Java Spring application with the Actuator endpoint enabled. The Actuator endpoint revealed an AWS Access Key and Heapdumps.. 130
Karim El-Melhaoui @karimscloud.bsky.social · 30/12/2024Cariad, a subsidiary of Volkswagen Group recently had a data compromise in AWS. Unlike my initial instinct, this was not related to a Public or Unprotected bucket.. Looking further into the breach, published by the Chaos Computer Club (ccc.de) responsible for the disclosure it was discovered by.. 154
Karim El-Melhaoui @karimscloud.bsky.social · 08/12/2024Great writeup on Azure OpenAI Abuse by Matt Graber redcanary.com/blog/threat-...redcanary.comArtificial authentication: Monitoring Azure OpenAI abuseAdversaries can compromise key material in Azure OpenAI to host malicious models, poison trained models, and steal intellectual property. 010
Karim El-Melhaoui @karimscloud.bsky.social · 02/12/2024Will dedicate two weekends of AWS research before it’s Christmas holiday 🫡 010
Karim El-Melhaoui @karimscloud.bsky.social · 02/12/2024First year I have FOMO for not attending #reinvent 110
Karim El-Melhaoui @karimscloud.bsky.social · 28/11/2024Spent some time on AWS research tonight. I’m looking forward to interact with the new vulnerability disclosure program 🫡 030
Reposted by Karim El-MelhaouiCody Burkard @codyburkard.com · 25/11/2024Are you an Azure Pentester looking for new lateral movement techniques? Take a look at my blog post about abusing Data Factory to steal secrets and tokens. Thanks @karimscloud.bsky.social for the inspiration to look into this. codyburkard.com/abusingselfh... 182
Karim El-Melhaoui @karimscloud.bsky.social · 22/11/2024Found Mimikatz binaries in allowlisted folders a few months ago. Was certain the server was compromised but turned out to be left from a pentest years ago.. 000
Karim El-Melhaoui @karimscloud.bsky.social · 21/11/2024OIDC seems to be an underrated attack vector. If you can get hold of a GitHub token you’re more or less guaranteed to find a repo that triggers a privileged service account / role from a pull_request in a lot orgs. 000
Karim El-Melhaoui @karimscloud.bsky.social · 18/11/2024Wrote some research on abusing Azure Data Factory www.o3c.no/knowledge/az... #cloudsecurityo3c.noAzure Data Factory - Abusing the Self-Hosted Integration RuntimeWe recently discovered that Azure Data Factory has a Self-Hosted Integration Runtime (SHIR), where we can create jobs that use credentials provided through the Azure Portal. 040
Karim El-Melhaoui @karimscloud.bsky.social · 18/11/2024Twitter has been dead for weeks, time to move on 080