Earlier quoted context omitted.
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…
I'm impressed you were able to get your employer (Salesforce) to actually let you publish this under their organization. Kudos to that.
Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
91–100 of 101 posts
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#92Earlier quoted context omitted.
Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…
404. Did they pull the repo or make it private? https://github.com/salesforce/endgame
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#93Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.
The repo is gone but the code is still on PyPI: https://pypi.org/project/endgame/
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#94Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#95Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#96Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#97Earlier quoted context omitted.
Not to sound like a jerk but why do you think this would be some "OMG" response from AWS? This is not some sort of "hacking", this is a tool that is being used to detect whether you misconfigured API access to be overly permissive. The tools job is to find them and them "abuse" them. Its not like AWS is not aware of user misconfigurations. The issue is AWS does not provide tools to detect these very well. Tools like…
And yet, it now 404s on both the salesforce project and the owners own personal GitHub.
This was more of a bad PR / Legal issue. AWS is well aware that people misconfigure permissions...
And again... better tools and more popular tools already existed... This is not new
https://rhinosecuritylabs.com/aws/pacu-open-source-aws-explo...
Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#98Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#99Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources
#100I work with AWS a lot every day and lead a team responsible for building workloads on AWS for some customers with very high security requirements. This tool terrifies me. The sheer amount of potential for misconfiguration of resources that this tool can exploit with no effort whatsoever is absolutely insane. I feel like every AWS environment I've ever seen is suddenly at risk of some angry employee compromising every…