DEV Community

Exploiting Common Serverless Security Flaws in AWS

Chris McQuaid on May 25, 2019

Overview Serverless and event-driven computing is gaining massive traction in not just the Start-Up space but in Enterprises as well, as...
Collapse
 
phlash profile image
Phil Ashby

Excellent, thanks Chris!

Taking this stuff back to the office next week as follow up on our pen testing that has been ongoing for a new AWS platform.. I'm gonna bet we've made at least one of these errors!

Collapse
 
thetestlabsio profile image
Chris McQuaid

Thanks, Phil - hope it helps!

If you're interested, I wrote a piece on using Pacu (an AWS exploitation framework) from RhinoSecurityLabs - might give you some ideas for testing your new platform. I'll pop it on here at some point, but at the moment it's on my personal blog - thetestlabs.io/post/hacking-aws/