Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
51–60 of 101 posts
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#52My first thought was "why is salesforce publishing essentially a hacking tool? why can't they bring it up privately, surely a large enough company will have some weight to their request?" but then I remembered AWS... >At the time of this writing, AWS Access Analyzer does NOT support auditing 11 out of the 18 services that Endgame attacks. Given that Access Analyzer is intended to detect this exact kind of violation,…
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#53Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#54Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#55Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#56Something tells me this is not AWS specific - how do GCP/Azure/Heroku stack up in comparison?
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#57Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#58404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?
Looks like some of it was archived though at https://web.archive.org/web/20210216153239/https://github.co....
Also still live at PyPI: https://pypi.org/project/endgame/
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#59Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#60It's gone now. :( I should have cloned it, anyone have a clone?
https://pypi.org/project/endgame/#files
I was thinking about putting a new repo with the code in it but I'd rather not risk the wrath of AWS since my job kinda depends on the service. Which probably says something about the state of Faang companies that I'm even concerned about it.