Getting Started with Hacking AWS ECS - a podcast by Kaizenteq Team

from 2023-01-12T11:36:04

:: ::

Cloud Security Podcast -  This month we are talking about "Breaking the AWS Cloud" and next up on this series, we spoke to Gafnit Amiga (Gafnit's Linkedin), VP of Security Research at Lightspin who recently discovered the AWS Elastic Container Registry Public (ECR Public) vulnerability. She spoke to us about how she goes about doing cloud security research and what AWS ECS and ECR is.


Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv


Host Twitter: Ashish Rajan (@hashishrajan)


Guest Twitter:  Gafnit Amiga (Gafnit's Linkedin)


Podcast Twitter - @CloudSecPod @CloudSecureNews


If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:


- Cloud Security News 


- Cloud Security Academy


Spotify TimeStamp for Interview Questions


(00:00) Introduction

(02:28) snyk.io/csp

(02:57) A bit about Gafnit

(05:15) What is AWS ECS and ECR?

(08:18) Why do people use ECS and ECR?

(09:58) The ECR vulnerability Gafnit discovered

(15:16) Vulnerability scanning for containers in AWS ECR

(16:42) How do you find undocumented APIs in AWS?

(17:58) Attack techniques in AWS

(22:43) How to protect your AWS accounts?

(25:14) Focus areas for Cloud Security Research in 2023

(25:48) Finding vulnerability through research

(29:00) Resources for Cloud Security Research


(31:04) The Fun Section


See you at the next episode!

Further episodes of Cloud Security Podcast

Further podcasts by Kaizenteq Team

Website of Kaizenteq Team