Видео докладов с конференции
DEF CON 33 Cloud Village стали доступны, с ними можно ознакомиться в трех плейлистах –
день первый,
второй и
третий.
Cloud Security:
Auths Gone Wild: When ‘Authenticated’ Means Anyone
- Wiz’s Danielle A. & Yaara Shriki
No IP, No Problem: Exfiltrating Data Behind Google’s Identity Aware Proxy
- Mitiga’s Ariel Kalman
Building the Cross-Cloud Kill Chain: A DE's Playbook for AWS, Azure & GCP Detections
- Meta’s Gowthamaraj Rajendran
whoAMI: Discovering and exploiting a large-scale AMI name confusion attack
- Datadog’s Seth Art
Weaponizing SSM: Practical Exploits and Hardening Techniques for AWS
- Clavis Security’s Rodrigo Montoro
Kubernetes:
Command and KubeCTL: Kubernetes Security for Pentesters and Defenders
- Chainguard’s Mark Manning
Spotter - Universal Kubernetes Security Engine
- Madhu Akula
Quickstart for a Breach! When Official Installations Expose Your K8 and Your Cloud
- Microsoft’s Michael Katchinskiy & Yossi Weizman
Don't trust Rufus, he's a mole - introducing KIEMPossible
- Palo Alto Networks Alto’s Golan Myers