Live data from Hacker News

Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

github.com

71–80 of 101 posts

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#72
post #4

My first thought was "why is salesforce publishing essentially a hacking tool? why can't they bring it up privately, surely a large enough company will have some weight to their request?" but then I remembered AWS... >At the time of this writing, AWS Access Analyzer does NOT support auditing 11 out of the 18 services that Endgame attacks. Given that Access Analyzer is intended to detect this exact kind of violation,…

Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…

Bugs get patched. Features are protected, and sometimes simultaneously abused. Thank you!

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#73

I work with AWS a lot every day and lead a team responsible for building workloads on AWS for some customers with very high security requirements. This tool terrifies me. The sheer amount of potential for misconfiguration of resources that this tool can exploit with no effort whatsoever is absolutely insane. I feel like every AWS environment I've ever seen is suddenly at risk of some angry employee compromising every…

[deleted]

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#74
nothing of security threat I guess. It uses your permissions, to modify the current permissions for different product. If u do have permissions to modify things, then this will work. if you have no permissions, it will fail.

So can it be used with bad intention, yes. But if I am a hacker, would i want to open all the available doors? or choose 1 or 2 doors only instead and keep the rest as is!!

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#75
post #58
post #55

404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?

It looks that way. Looks like some of it was archived though at https://web.archive.org/web/20210216153239/https://github.co... . Also still live at PyPI: https://pypi.org/project/endgame/

pypi tgz at archive.org: https://web.archive.org/web/20210216214208/https://files.pyt...

Also https://github.com/hirajanwin/endgame is still up as of 00:58 Wednesday, February 17, 2021 Coordinated Universal Time (UTC). Zip file download of that Git repo here: https://web.archive.org/web/20210217005905/https://codeload....

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#76
post #4

My first thought was "why is salesforce publishing essentially a hacking tool? why can't they bring it up privately, surely a large enough company will have some weight to their request?" but then I remembered AWS... >At the time of this writing, AWS Access Analyzer does NOT support auditing 11 out of the 18 services that Endgame attacks. Given that Access Analyzer is intended to detect this exact kind of violation,…

Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…

404. Did they pull the repo or make it private?

https://github.com/salesforce/endgame

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#77
post #55

404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?

Moved to his personal: https://github.com/kmcquade/endgame

Now a 404.

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#78
post #55

404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?

Moved to his personal: https://github.com/kmcquade/endgame

Give

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#79
post #55

404? someone got an urgent call from AWS and politely requested to remove it since both companies are supposed to be partners?

Moved to his personal: https://github.com/kmcquade/endgame

Gone
Post reply on HN