July 12, 2023, 5:48 p.m. | John Hammond

John Hammond www.youtube.com

For another fireworks show, Ignacio Dominguez and Carlos Polop from HALBORN showcase how dependency confusion attacks can occur with the AWS CodeArtifact service -- potentially even having npm execute rogue code just upon install.

You can learn more about security assessments and cloud testing Halborn does at https://jh.live/halborn

00:00 Preview
00:22 Background on AWS Man-in-the-Middle
01:02 AWS CodeArtifact
02:34 Remote Code Execution with Dependency Confusion
04:34 You need to update old defaults!
05:22 Begin Demonstration
07:12 New Panel "Edit Origin …

attacks aws code code execution dependency dependency confusion dependency confusion attacks fireworks halborn install man-in-the-middle npm preview remote code remote code execution rogue service

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineer - Vulnerability Management

@ Starling Bank | Southampton, England, United Kingdom

Manager Cybersecurity

@ Sia Partners | Rotterdam, Netherlands

Compliance Analyst

@ SiteMinder | Manila

Information System Security Engineer (ISSE)-Level 3, OS&CI Job #447

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Enterprise Cyber Security Analyst – Advisory and Consulting

@ Ford Motor Company | Mexico City, MEX, Mexico