{"id":12512,"date":"2020-01-07T00:13:00","date_gmt":"2020-01-06T23:13:00","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=12512"},"modified":"2020-01-06T22:49:46","modified_gmt":"2020-01-06T21:49:46","slug":"ntzliche-tools-fr-die-aws-cloud-sicherheit","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2020\/01\/07\/ntzliche-tools-fr-die-aws-cloud-sicherheit\/","title":{"rendered":"Useful tools for AWS cloud security"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"http:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2014\/02\/OneDrive.jpg\" width=\"58\" align=\"left\" height=\"56\">[<a href=\"https:\/\/www.borncity.com\/blog\/?p=226648\" target=\"_blank\" rel=\"noopener noreferrer\">German<\/a>]A tip for people who are responsible for the administration of Amazon Cloud Solutions (AWS etc.). In order to detect weaknesses early, you should be aware of the IP addresses and subdomains used. <\/p>\n<p><!--more--><\/p>\n<p>An orphaned subdomain that refers to a service that no longer exists could be taken over by a third party (this has happened many times before). However, there are tools that can be used to check whether, for example, subdomains refer to services that no longer exist and can thus be taken over. Other tools allow you to list all subdomains or public IP addresses associated with an AWS account. <\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Sub-Domain TakeOver Vulnerability Scanner<a href=\"https:\/\/t.co\/sxN38nAiwo\">https:\/\/t.co\/sxN38nAiwo<\/a><\/p>\n<p>Recursive DNS Subdomain Enumerator<a href=\"https:\/\/t.co\/B9bFhdEQ5U\">https:\/\/t.co\/B9bFhdEQ5U<\/a><\/p>\n<p>ReconPi &#8211; A lightweight recon tool<a href=\"https:\/\/t.co\/vVJXIeVntx\">https:\/\/t.co\/vVJXIeVntx<\/a><\/p>\n<p>Fetch all public IP addresses tied to your AWS account<a href=\"https:\/\/t.co\/sM9QF8A3zQ\">https:\/\/t.co\/sM9QF8A3zQ<\/a><a href=\"https:\/\/twitter.com\/hashtag\/bugbounty?src=hash&amp;ref_src=twsrc%5Etfw\">#bugbounty<\/a><\/p>\n<p>\u2014 A hacker's life (@Unknownuser1806) <a href=\"https:\/\/twitter.com\/Unknownuser1806\/status\/1214167367170719744?ref_src=twsrc%5Etfw\">January 6, 2020<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script> <\/p>\n<p>The tweet above contains links to various tools available on GitHub to support specific tasks in this area. It might help some blog readers<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]A tip for people who are responsible for the administration of Amazon Cloud Solutions (AWS etc.). In order to detect weaknesses early, you should be aware of the IP addresses and subdomains used.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,580],"tags":[64,69],"class_list":["post-12512","post","type-post","status-publish","format-standard","hentry","category-cloud","category-security","tag-cloud","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/12512","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=12512"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/12512\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=12512"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=12512"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=12512"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}