June 28, 2023, 1 p.m. | John Hammond

John Hammond www.youtube.com

Carlos Polop from HALBORN showcases his technique to exfiltrate Github tokens via the AWS CodeBuild cloud service, with a custom Docker container to man-in-the-middle the OAuth credentials!

You can learn more about Carlos Polop, Ignacio Dominguez or the security audits and assessments that HALBORN performs at https://j-h.io/halborn

Check out the vulnerability disclosure writeup from HALBORN: https://www.halborn.com/blog/post/halborn-discovers-and-discloses-vulnerability-in-aws-code-build

00:00 Preview
00:20 Introduction with Carlos & Ignacio
01:00 AWS CodeBuild Background
02:12 CodeBuild and GitHub Mishaps
05:12 Execute CodeBuild within a Docker Container …

amp aws cloud cloud service container credentials demo docker github halborn introduction man-in-the-middle oauth preview service stealing tokens

Senior Security Officer

@ eSimplicity | Remote

Senior - Automated Cyber Attack Engineer

@ Deloitte | Madrid, España

Public Key Infrastructure (PKI) Senior Engineer

@ Sherwin-Williams | Cleveland, OH, United States

Consultant, Technology Consulting, Cyber Security - Privacy (Senior) (Multiple Positions) (1502793)

@ EY | Chicago, IL, US, 60606

Principal Associate, CSOC Analyst

@ Capital One | McLean, VA

Real Estate Portfolio & Corporate Security Lead

@ Lilium | Munich