Intruder researcher and penetration tester Daniel Thatcher has disclosed an AWS API Gateway flaw which allowed him to bypass the API Gateway’s IP address restrictions and wage a cache-poisoning attack using so-called HTTP header-smuggling. Yariv Shivek, VP of Product, Neosec had this to say:
“When working with B2B partners, many companies use IP address whitelisting over the more cumbersome implementation of mTLS (mutual transport layer security). In this case, IP whitelisting was bypassed using request header smuggling.”
“The bigger picture here is that we keep seeing security controls evaded and bypassed, which in turn speaks to the importance of monitoring API usage.”
“Since bad actors will eventually get to your APIs and use them, the question then becomes one of visibility: Will you be able to see the abnormal usage patterns in order to shut them down?”
AWS has since fixed the vulnerability, which means that this is no longer exploitable. But it is still a concern that needs to be discussed as these sorts of security issues simply cannot be swept under the rug.
Related
This entry was posted on November 11, 2021 at 8:57 am and is filed under Commentary with tags Security. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
AWS API Gateway “Header-Smuggling” Flaw Discovered And Fixed
Intruder researcher and penetration tester Daniel Thatcher has disclosed an AWS API Gateway flaw which allowed him to bypass the API Gateway’s IP address restrictions and wage a cache-poisoning attack using so-called HTTP header-smuggling. Yariv Shivek, VP of Product, Neosec had this to say:
“When working with B2B partners, many companies use IP address whitelisting over the more cumbersome implementation of mTLS (mutual transport layer security). In this case, IP whitelisting was bypassed using request header smuggling.”
“The bigger picture here is that we keep seeing security controls evaded and bypassed, which in turn speaks to the importance of monitoring API usage.”
“Since bad actors will eventually get to your APIs and use them, the question then becomes one of visibility: Will you be able to see the abnormal usage patterns in order to shut them down?”
AWS has since fixed the vulnerability, which means that this is no longer exploitable. But it is still a concern that needs to be discussed as these sorts of security issues simply cannot be swept under the rug.
Share this:
Like this:
Related
This entry was posted on November 11, 2021 at 8:57 am and is filed under Commentary with tags Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.