HOSTED BY CODY Threat Aware // PRIVILEGE ESCALATION // EP03

How Hackers Walk Into Your Cloud

An attacker pastes a link into an ordinary web form and walks away with the keys to the company's whole cloud. No password, no malware. Cody Kretsinger breaks down how that kind of attack works, why it's still effective today, and the fix that's been around for years.

WATCH / LISTEN

One attack, told properly. Each episode takes a single breach or backdoor apart: how it was built, who caught it, and what almost happened instead. Part of Galactic's Threat Aware.

Transcript

Auto-generated transcript, apologies for any errors. Download as text

Cold open

Imagine you build a feature everybody builds. A little box where a user pastes a link, maybe a photo, and the app goes and fetches it. It grabs the image, shows it on the page. That's totally normal. Practically every app on Earth does this. Except, now I don't paste a photo. I paste an address that only your server can reach. A secret one inside your own cloud infrastructure. And Your server, being helpful, goes and asks it from me. So what happens next? That address I pointed your server to hands back the keys to your entire cloud account.

Not a password, not one file, the keys to everything. Your own server asks for them, but on my behalf, because I said please in the language it didn't know it spoke.

Narrator

This is Privilege Escalation. Part of the Threat Aware Podcast Network. Incidents get reported. They rarely get explained. Each episode takes one attack apart from the inside, delivered with the perspective of someone who has spent time on both sides of an attack. How they got in, and how you stop them. Here's your host, Cody Kretsinger.