Keeping an eye on RDS vulnerabilities. episode artwork

EPISODE · Sep 24, 2022 · 16 MIN

Keeping an eye on RDS vulnerabilities.

from Research Saturday · host N2K Networks

Gafnit Amiga, Director of Security Research from Lightspin, joins Dave to discuss her team's research "AWS RDS Vulnerability Leads to AWS Internal Service Credentials." The research describes how the vulnerability was caught and right after it was reported, the AWS Security team applied an initial patch limited only to the recent Amazon Relational Database Service (RDS) and Aurora PostgreSQL engines, excluding older versions. They followed by personally reaching out to the customers affected by the vulnerability and helped them through the update process. The research states "Lightspin's Research Team obtained credentials to an internal AWS service by exploiting a local file read vulnerability on the RDS EC2 instance using the log_fdw extension." The research can be found here: AWS RDS Vulnerability Leads to AWS Internal Service Credentials

Episode metadata supplied by the publisher feed · Published Sep 24, 2022

Embed this episode

NOW PLAYING

Keeping an eye on RDS vulnerabilities.

0:00 16:11

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Research Saturday?

This episode is 16 minutes long.

When was this Research Saturday episode published?

This episode was published on September 24, 2022.

Can I download this Research Saturday episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!