Remove about-us cookies-policy
article thumbnail

Using undocumented AWS APIs

Xebia

TL;DR just give me the code While evaluating some existing IAM policies in a codebase, I found myself repeating the same steps over and over again: navigate Google and search iam actions servicename and look up information about the actions used. This uses the __getattribute__ override and the methods object.

AWS 147
article thumbnail

FlowFixation: AWS Apache Airflow Service Takeover Vulnerability and Why Neglecting Guardrails Puts Major CSPs at Risk

Tenable

Some significant risks due to the misconfiguration included cookie tossing, which can lead to session fixation abuse and cross-site request forgery (CSRF) protection bypass; and same-site cookie protection bypass. Cookie-tossing attacks can also abuse session-fixation issues.

AWS 127
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Extra Crunch roundup: TC Mobility recaps, Nubank EC-1, farewell to browser cookies

TechCrunch

Reporter Marcella McCarthy spoke to CEO David Velez to learn about his efforts to connect with consumers and overcome entrenched opposition from established players who were friendly with regulators. In the first of a series of stories for Nubank’s EC-1 , she interviewed Velez about his early fundraising efforts.

Mobile 198
article thumbnail

How To Build Safe And ‘PROUD’ Workplaces – A Personal Story

Hacker Earth Developers Blog

As a conscious employee, I always made sure to join companies that had a D&I charter in place; with documented policies and growth metrics. At the end of the day, that’s what’s important to feel included – a reflection of our own selves in the environment around us. And this brings us to June, 2019. The one being me.

How To 283
article thumbnail

India’s Daalchini raises $4M to make smart stores and vending machines ubiquitous

TechCrunch

The startup has also tied up with companies including Byju’s, Reliance, Aditya Birla Group’s Hindco, Vodafone, Samsung and EY and organizations including the country’s public policy think tank NITI Aayog to deploy its vending machines. About 30% of the total franchisee partners comprise woman entrepreneurs, she said.

Retail 189
article thumbnail

ApatchMe - Authenticated Stored XSS Vulnerability in AWS and GCP Apache Airflow Services

Tenable

In response, AWS now offers a new, non-vulnerable version of Apache Airflow and, for the unpatched versions, has added a CSP (Content Security Policy) as a guardrail. Microsoft Azure also uses vulnerable managed Apache Airflow instances in its Data Factory service. GCP is working on releasing a new, non-vulnerable version.

article thumbnail

TechCrunch+ roundup: Collecting zero-party data, Airbnb CEO interview, crypto volatility

TechCrunch

For most of the internet era, that work was performed with tools like browser cookies and tracking pixels, but consumer desire for greater privacy (and increased regulation) is forcing online marketers to rethink basic practices. What if instead of surreptitiously tracking our behavior, they just asked us for relevant details?

Data 199