Главная
Study mode:
on
1
Introduction
2
Agenda
3
Serverless Evolution
4
The Magic
5
The Benefits
6
The Downsides
7
The Competitors
8
AWS Lambda
9
AWS Lambda Functions
10
Security
11
Lambda Security
12
Challenge Accepted
13
Playground
14
URL
15
Example
16
What is Code Injection
17
lambda test route
18
exfiltration
19
payload
20
hacker container
21
AWS Lambda Documentation
22
Update Lambda Functions
23
Clean House
24
Users
25
Persistent Infection
26
Reset Function
27
CrossContamination
28
Execution Roll
29
Full Access
30
Sample
31
VPC
32
Amazon VPC
33
Key takeaways
34
Questions
Description:
Explore the emerging threat of serverless infections in this eye-opening conference talk from BSidesLV 2018. Delve into the evolution of serverless computing, focusing on AWS Lambda and its security implications. Learn about the benefits and downsides of serverless architectures, and witness a live demonstration of code injection techniques targeting Lambda functions. Discover how malware can exploit serverless environments, including methods for persistence, cross-contamination, and privilege escalation. Gain key insights into protecting serverless infrastructures and understand the potential risks associated with this new frontier in cloud computing. Equip yourself with essential knowledge to safeguard against serverless-based attacks in this comprehensive 41-minute presentation by security expert Erez Yalon.

Serverless Infections - Malware Just Found a New Home

BSidesLV
Add to list
0:00 / 0:00