Live data from Hacker News

Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

github.com

51–60 of 101 posts

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#52
post #4

My first thought was "why is salesforce publishing essentially a hacking tool? why can't they bring it up privately, surely a large enough company will have some weight to their request?" but then I remembered AWS... >At the time of this writing, AWS Access Analyzer does NOT support auditing 11 out of the 18 services that Endgame attacks. Given that Access Analyzer is intended to detect this exact kind of violation,…

Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…

Can you share the code somewhere else? It's been taken down from github

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#54
post #47

Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.

I don't know that I would call them a direct competitor. Heroku uses AWS for a lot of it's infrastructure. They are a pretty big AWS customer.

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#56
post #15

Something tells me this is not AWS specific - how do GCP/Azure/Heroku stack up in comparison?

I for one would specifically be interested in someone's review of Azure Defender, since it claims to be able to handle AWS and GCP

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#57
post #47

Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.

The repo is gone but the code is still on PyPI: https://pypi.org/project/endgame/

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#58
post #55

404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?

It looks that way.

Looks like some of it was archived though at https://web.archive.org/web/20210216153239/https://github.co....

Also still live at PyPI: https://pypi.org/project/endgame/

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#60
post #53

It's gone now. :( I should have cloned it, anyone have a clone?

Not a clone but you can download the code from here:

https://pypi.org/project/endgame/#files

I was thinking about putting a new repo with the code in it but I'd rather not risk the wrath of AWS since my job kinda depends on the service. Which probably says something about the state of Faang companies that I'm even concerned about it.

Post reply on HN