Ur Shellz Belong to AWS: Pentesting challenges against serverless environments

No ratings

Presented at BSidesDFW 2018 by

Finding a remote code execution vulnerability to get shell on a S3 bucket? How about persistence on a Lambda or Google Cloud function? The game is different now and penetration testers should take heed. Web architecture has moved from on-prem to DevOps CI/CD infrastructure deployment in the cloud and has now moved serverless...what the $&%# is serverless? Serverless is the application model that is changing the attack surface that is traditionally known by web application penetration testers, and allows developers to no longer focus on infrastructure provisioning, patch management, scaling, and much more. The burden of infrastructure is being offloaded to cloud providers, along with its associated security risks. If your next pentest was a serverless application, how much of your existing attack methodology would still apply? Here we examine this application model and discuss exactly how the game has changed.