Live data from Hacker News

Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

github.com

91–100 of 101 posts

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#91
post #16
post #4

Earlier quoted context omitted.

Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…

I'm impressed you were able to get your employer (Salesforce) to actually let you publish this under their organization. Kudos to that.

I guess they didn't.

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#92
post #4

Earlier quoted context omitted.

Author here :) Endgame exploits/abuses features. If it was a bug, I'd work with AWS to solve the problem, but with abusing features - that would result in years of unsatisfied feature requests. This should push the issue along. >...and it's not even a hacking tool! It can be used to backdoor resources to rogue accounts, so I'd say it's a hacking tool and can/should be used on penetration tests. I'd certainly use it o…

404. Did they pull the repo or make it private? https://github.com/salesforce/endgame

Here is one of many forks: https://github.com/agnivesh/endgame/

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#93
post #47

Anybody have a mirror? It seems to have been taken down from GitHub. Also I guess it might have been a not so nice from an almost direct competitor of AWS - salesforce - to publish something like that. Salesforce owns heroku.

The repo is gone but the code is still on PyPI: https://pypi.org/project/endgame/

Also gone

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#95
post #16

Earlier quoted context omitted.

I'm impressed you were able to get your employer (Salesforce) to actually let you publish this under their organization. Kudos to that.

I guess they didn't.

That’s what I was expecting to happen, unfortunately.

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#97

Earlier quoted context omitted.

Not to sound like a jerk but why do you think this would be some "OMG" response from AWS? This is not some sort of "hacking", this is a tool that is being used to detect whether you misconfigured API access to be overly permissive. The tools job is to find them and them "abuse" them. Its not like AWS is not aware of user misconfigurations. The issue is AWS does not provide tools to detect these very well. Tools like…

And yet, it now 404s on both the salesforce project and the owners own personal GitHub.

And? Thats not because "AWS" was like "OMG so smart", AWS is already well aware of this issue but lays the blame on "Shared Responsibility" and are likely annoyed that Salesforce, a partner of AWSHonestly, my guess is there was a lapse in Salesforce somewhere, where either legal or PR didn't check this because this likely goes against Salesforce and AWS NDA for their partnership. I worked as an AWS partner before, there are requirements that go into place before you can release stuff like this to the public. Plus, having worked with Salesforce as well, I assume they have a PR policy to not use the word "hacking" in tool names or description, especially in regards to partners. My company has similar rules for OSS stuff.

This was more of a bad PR / Legal issue. AWS is well aware that people misconfigure permissions...

And again... better tools and more popular tools already existed... This is not new

https://rhinosecuritylabs.com/aws/pacu-open-source-aws-explo...

Re: Show HN: Endgame – An AWS Pentesting tool to backdoor or expose AWS resources

#100

I work with AWS a lot every day and lead a team responsible for building workloads on AWS for some customers with very high security requirements. This tool terrifies me. The sheer amount of potential for misconfiguration of resources that this tool can exploit with no effort whatsoever is absolutely insane. I feel like every AWS environment I've ever seen is suddenly at risk of some angry employee compromising every…

404 on this today so I guess they were terrified.
Post reply on HN