No keys to the kingdom required

Manuel Karl, Marius Musch, Guoli Ma, Martin Johns, Sebastian Lekies · 2022

Nowadays, applications expose administrative endpoints to the Web that can be used for a plethora of security sensitive actions. Typical use cases range from running small snippets of user-provided code for rapid prototyping, administering databases, and running CI/CD pipelines, to managing job scheduling on whole clusters of computing devices. While accessing these applications over the Web make the lives of their users easier, they can be leveraged by attackers to compromise the underlying infrastructure if not properly configured.

Read the paper · More papers on PaperTik