Artwork

内容由Corey Quinn提供。所有播客内容(包括剧集、图形和播客描述)均由 Corey Quinn 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal
Player FM -播客应用
使用Player FM应用程序离线!

Replay - Hacking AWS in Good Faith with Nick Frichette

32:32
 
分享
 

Manage episode 457590976 series 2937944
内容由Corey Quinn提供。所有播客内容(包括剧集、图形和播客描述)均由 Corey Quinn 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

On this Screaming in the Cloud Replay, we’re taking you back to our chat with Nick Frichette. He’s the maintainer of hackingthe.cloud, and holds security and solutions architect AWS certifications, and in his spare time, he conducts vulnerability research at Hacking the Cloud. Join Corey and Nick as they talk about the various kinds of cloud security researchers and touch upon offensive security, why Nick decided to create Hacking the Cloud, how AWS lets security researchers conduct penetration testing in good faith, some of the more interesting AWS exploits Nick has discovered, how it’s fun to play keep-away with incident response, why you need to get legal approval before conducting penetration testing, and more.

Show Highlights

(0:00) Intro

(0:42) The Duckbill Group sponsor read

(1:15) What is a Cloud Security Researcher?

(3:49) Nick’s work with Hacking the Cloud

(5:24) Building relationships with cloud providers

(7:34) Nick’s security findings through cloud logs

(13:05) How Nick finds security flaws

(15:31) Reporting vulnerabilities to AWS and “bug bounty” programs

(18:41) The Duckbill Group sponsor read

(19:24) How to report vulnerabilities ethically

(21:52) Good disclosure programs vs. bad ones

(28:23) What’s next for Nick

(31:27) Where you can find more from Nick

About Nick Frichette

Nick Frichette is a Staff Security Researcher at Datadog, specializing in offensive security within AWS environments. His focus is on discovering new attack vectors targeting AWS services, environments, and applications. From his research, Nick develops detection methods and preventive measures to secure these systems. Nick’s work often leads to the discovery of vulnerabilities within AWS itself, and he collaborates closely with Amazon to ensure they are remediated.

Nick has also presented his research at major industry conferences, including Black Hat USA, DEF CON, fwd:cloudsec, and others.

Links

Original Episode

https://www.lastweekinaws.com/podcast/screaming-in-the-cloud/hacking-aws-in-good-faith-with-nick-frichette/

Sponsor

The Duckbill Group: duckbillgroup.com

  continue reading

630集单集

Artwork
icon分享
 
Manage episode 457590976 series 2937944
内容由Corey Quinn提供。所有播客内容(包括剧集、图形和播客描述)均由 Corey Quinn 或其播客平台合作伙伴直接上传和提供。如果您认为有人在未经您许可的情况下使用您的受版权保护的作品,您可以按照此处概述的流程进行操作https://zh.player.fm/legal

On this Screaming in the Cloud Replay, we’re taking you back to our chat with Nick Frichette. He’s the maintainer of hackingthe.cloud, and holds security and solutions architect AWS certifications, and in his spare time, he conducts vulnerability research at Hacking the Cloud. Join Corey and Nick as they talk about the various kinds of cloud security researchers and touch upon offensive security, why Nick decided to create Hacking the Cloud, how AWS lets security researchers conduct penetration testing in good faith, some of the more interesting AWS exploits Nick has discovered, how it’s fun to play keep-away with incident response, why you need to get legal approval before conducting penetration testing, and more.

Show Highlights

(0:00) Intro

(0:42) The Duckbill Group sponsor read

(1:15) What is a Cloud Security Researcher?

(3:49) Nick’s work with Hacking the Cloud

(5:24) Building relationships with cloud providers

(7:34) Nick’s security findings through cloud logs

(13:05) How Nick finds security flaws

(15:31) Reporting vulnerabilities to AWS and “bug bounty” programs

(18:41) The Duckbill Group sponsor read

(19:24) How to report vulnerabilities ethically

(21:52) Good disclosure programs vs. bad ones

(28:23) What’s next for Nick

(31:27) Where you can find more from Nick

About Nick Frichette

Nick Frichette is a Staff Security Researcher at Datadog, specializing in offensive security within AWS environments. His focus is on discovering new attack vectors targeting AWS services, environments, and applications. From his research, Nick develops detection methods and preventive measures to secure these systems. Nick’s work often leads to the discovery of vulnerabilities within AWS itself, and he collaborates closely with Amazon to ensure they are remediated.

Nick has also presented his research at major industry conferences, including Black Hat USA, DEF CON, fwd:cloudsec, and others.

Links

Original Episode

https://www.lastweekinaws.com/podcast/screaming-in-the-cloud/hacking-aws-in-good-faith-with-nick-frichette/

Sponsor

The Duckbill Group: duckbillgroup.com

  continue reading

630集单集

Todos los episodios

×
 
Loading …

欢迎使用Player FM

Player FM正在网上搜索高质量的播客,以便您现在享受。它是最好的播客应用程序,适用于安卓、iPhone和网络。注册以跨设备同步订阅。

 

快速参考指南

边探索边听这个节目
播放