ã¢ãã»ãã¥ãªãã£ã§è©±ããå 容ã§ãã https://mob-security.connpass.com/event/209884/ æ å ±ã®å«ççãªåãæ±ãããé¡ããã¾ãã
ã¢ãã»ãã¥ãªãã£ã§è©±ããå 容ã§ãã https://mob-security.connpass.com/event/209884/ æ å ±ã®å«ççãªåãæ±ãããé¡ããã¾ãã
ã¯ããã« ååã®ããã°ã§ã¯ããã«ãã¢ã«ã¦ã³ãã«ãããIAMã¦ã¼ã¶ã¼ã®è¨è¨æ¦ç¥ã«ã¤ãã¦ãç´¹ä»ãã¾ããã ä»åã¯å°ããã¼ããå¤ãã以åçè ãJAWS DAYS 2020ã§ç»å£ããã¦ããã ããCI/CDã®å 容ãåºã«ããã¼ã¿ä¿è·ã®è¦³ç¹ããã®è¨è¨~å®è£ ãåãä¸ãããã¨æãã¾ãã â»å°ã ã硬ãå 容ãå«ã¿ã¾ãããAWS CI/CDã»ãã¥ãªãã£ãèããä¸ã§ä¸ã¤ã®ãã¤ã³ãã«ãªãã¯ããªã®ã§ããèå³ããæã¡ã®æ¹ã¯æ¯éãä»ãåããã ãããm(_ _)m ååãç´¹ä»ããCI/CDå 容ã®ãããã JAWSDAYS2020ã«ã¦ãéèãµã¼ãã¹åãã«çæ³ã®CI/CDã追ãæ±ããã話ãã¨ããã¿ã¤ãã«ã§ãçè ãæ å½ãããµã¼ãã¹ã®CI/CDè¨è¨ããç´¹ä»ãããã¾ããã ããã§ããçæ³ãã¨ããç¹ã«ã¤ãã¦ããä¸åº¦æ¯ãè¿ãã¨ãããã¯ãCI/CDå°å ¥ã«ããæå¾ ãããã¨ãã¨ããæ¥åç¹æ§ã¨ãã¦å®ããªããã°ãªããªããã¨ãã®ä¸¡ç«ã§ããã é«ã¢ã¸ãª
AWS ã§ç°å¢ãæ§ç¯ããéã¯ãã«ãã¢ã«ã¦ã³ãã«ãªããã¨ãå¤ããããã¯ç解ãã¦ããã¤ããã§ããã stg ç°å¢ã¨ prod ç°å¢ã¯ AWS ã¢ã«ã¦ã³ããã¨åãããdev ç°å¢ãåããã ããããä¸ã®ä¸ã®ãã¹ããã©ã¯ãã£ã¹ã¯ãã£ã¨å ãè¡ã£ã¦ãã¾ããã ãªãã¢ã«ã¦ã³ããåããã®ã isolation authz & authn auditing and reporting ä¸ã®ä¸ã®ãã«ãã¢ã«ã¦ã³ãæ§æ åä¼æ¥ã®äºä¾ AWS ãæä¾ãããã¹ããã©ã¯ãã£ã¹ Gruntwork ããè¦ã AWS ãã¹ããã©ã¯ãã£ã¹ å社ã®ãã©ã¯ãã£ã¹ããèªã¿åããã㨠ãªãã¢ã«ã¦ã³ããåããã®ã AWS ã¢ã«ã¦ã³ããåããçç±ã¯ 3 ã¤ããã¾ãã isolation authz & anthn auditing and reporting isolation ããããã¨ãã¦ãç°å¢ã¯åé¢ããªãã¨ãã¨ãããã®ã§ãã st
Amazon Web Services ããã° AWS ã¢ã«ã¦ã³ãã®ã»ãã¥ãªãã£ãæ¹åããããã® 10 åã®é ç® ã¯ã©ã¦ãã»ã»ãã¥ãªãã£ãåä¸ããããã¨èãã¦ãããªããAWS ã®ãã¼ãã»ã¤ã³ãã©ã¡ã¼ã·ã§ã³ã»ã»ãã¥ãªãã£ã»ãªãã£ãµã¼ (CISO) ã§ããã¹ããã¡ã³ã»ã·ã¥ãããã AWS re:Invent 2019ã§çºè¡¨ããã¯ã©ã¦ãã»ã»ãã¥ãªãã£ã®ããã®ä¸ä½ 10 åã®é ç® ãåç §ãã¦ã¿ã¦ã¯ãããã§ããããï¼ ä¸è¨ãé ç®ã®ãµããªã¼ã§ããçæ§ã®ç解ã®ããã«ãé çªã«èª¬æãã¦ããã¾ãã 1) ã¢ã«ã¦ã³ãæ å ±ãæ£ããä¿ã¤ AWS ã AWS ã¢ã«ã¦ã³ãã«ã¤ãã¦é£çµ¡ãå¿ è¦ãªå ´åãAWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã§è¨å®ãããé£çµ¡å ã®æ å ±ãå©ç¨ãã¾ããããã¯ãã¢ã«ã¦ã³ããä½æããæã«æå®ãã E ã¡ã¼ã«ã¢ãã¬ã¹ã代æ¿ã®é£çµ¡å ã®ä¸ã§æå®ããã¦ãã E ã¡ã¼ã«ã¢ãã¬ã¹ã«ãªãã¾ããå ¨ã¦ã® E ã¡ã¼ã«ã¢ãã¬ã¹ã¯å人
Amazon Web Services ããã° ã¯ã©ã¦ãã«ãããå®å ¨ãªãã¼ã¿ã®å»æ£ ã¯ã©ã¦ãã«ãããçµ±å¶ãã客æ§ãèæ ®ããå ´åãåºæ¬çãªèãæ¹ã¯å¤§ããç°ãªããã®ã§ã¯ããã¾ããããã ããã¯ã©ã¦ããªãã§ã¯ã®çµ±å¶ãèæ ®ãã¹ãã±ã¼ã¹ããããã¨ãäºå®ã§ãããã®éã«ã¯ãå¾æ¥ã®ãªã³ãã¬ãã¹ã®ããæ¹ãç¡çã«ã¯ã©ã¦ãã«å½ã¦ã¯ãããã¨ãã¦ããã¾ãã¯è¡ãã¾ããã大äºãªãã¨ã¯ãã®çµ±å¶ãä½ãç®çã¨ãã¦ããã®ãã«ç«ã¡è¿ãããã®ä¸ã§ãNew normal(æ°ãã常è)ã«ãã£ãèãæ¹ãå®è£ ãããããå¿ è¦æ§ãç解ããå®è·µãããã¨ã§ãããã®æ稿ã§ã¯ãã¡ãã£ã¢ããã¼ã¿ã®å»æ£ãä¾ã¨ãã¦ãã»ãã¥ãªãã£ã®New normalãèãã¦ããã¾ãã ã¡ãã£ã¢å»æ£ã«ãããç°å¢ã®å¤å ãã¼ã¿ã®ã©ã¤ããµã¤ã¯ã«ã«å¿ããæ å ±è³ç£ã®ç®¡çã¯å¤ãã®ã客æ§ã®é¢å¿äºé ã§ãã ãªã³ãã¬ãã¹ã®çµ±å¶ã¨ã®å¤æ´ã¨ãã観ç¹ã§ã¯ãã¡ãã£ã¢å»æ£æã®çµ±å¶ã¯å¾æ¥ã®ãªã³ãã¬ãã¹ç°
2019å¹´8æã«çºçãã Capital Oneã®ãã¼ã¿æ¼æ´©äºä»¶ã«é¢ããåç¨®å ±éçã®æ å ±ãããã®ãã¼ã¿æ¼æ´©çµè·¯ãèå¯ãããFBIã®èµ·è¨´ç¶ãCapitalOneã®å ¬å¼çºè¡¨ã®ã»ããã¤ã³ã¿ã¼ãããä¸ã§å ±éããã¦ããå種æ å ±ããèå¯ããã¦ãããå 容ã«ã¯æ¨æ¸¬ãå«ã¾ããã ãªãæ¬èå¯ã¯å人çãªèª¿æ»ã«åºã¥ããã®ã§ããããããªãå ¬å¼çºè¡¨ã§ããªããæè¡çãªè¦³ç¹ããäºè±¡ã対çã«ã¤ãã¦æ¤è¨ãããã®ã§ããã æ¼æ´©ãããã¼ã¿S3ãã±ããã«ä¿åããã¦ãããã¼ã¿ãæ¼æ´©ãããã¾ãéå ¬å¼ãªæ å ±ã§ã¯ãTwitterã§ç¯è¡ãåç¥ãã¦ããã¡ãã»ã¼ã¸ããèªã¿åãã«ãEBS Volume Snapshotãæ¼æ´©ããå¯è½æ§ãããã åå¾ããã¨ãããã¼ã¿ã®ãªã¹ã (KrebsOnSecurityãã)主ãªæ¼æ´©ã®æµãæ§æãã¹ããã£ãWAF (Reverse Proxyã¨ã)ãå©ç¨ããããã®å¾ã«S3ãã±ããå ã«ãã£ããã¼ã¿ãªã©ãæ¼æ´©ããã
Automate Your AWS WAF operations Save time and cost on maintaining your AWS WAF Do what you do best, let WafCharm do the rest With WafCharm, AWS WAF operations are automated as it automatically configures, curates, and updates AWS WAF rules that best fit your environment. Additionally, with a full team of security experts, WafCharm always stays ahead of new vulnerabilities by creating and applying
å æ¥twitterãè¦ã¦ãããããããªã¤ã¶ãããæè¦ãã¦ãå人çã«ä¾µå ¥ãã¹ãç³è«ã«ã¯è²ã æãå ¥ãã®ãã身ã§ãããããããã¯ãªãããã¨ãã診æå¡ãã§ãã ããï¼AWSã®ä¾µå ¥ãã¹ãç³è«ãããªããªãã¾ããï¼ pic.twitter.com/Z6ULU10SMyâ ä¸ãç¢ â=3 (@328__) March 1, 2019 ãã®ããã°ã§ãã¨ãããã¾ããããä»ã¾ã§AWSã¯ãããã¬ã¼ã·ã§ã³ãã¹ããèå¼±æ§è¨ºæãªã©ãå®æ½ããéã«ãAWSå´ã¸ã®äºåã®ç³è«ãå¿ è¦ã ã£ãã®ã§ãããä»åããªã·ã¼ã®å¤æ´ããã£ããããã©ãããä¸è¦ã«ãªã£ãããã§ãã ã¨ãããã¨ã§ãç§ãèªåã§ç¢ºèªããã¦ã¿ã¾ããã Penetration Testing - Amazon Web Services (AWS) ç¾å¨æ¥æ¬èªçãµã¤ãã¯ã翻訳ãéã«åã£ã¦ãªãããã§ã¾ã æ´æ°ããã¦ãªãããã§ããï¼2019/3/5確èªï¼ãè±èªçã®æ¹ã¯è¨è¼å 容ãã¬ã©ãª
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã ã¦ã§ããã¼ã±ãã£ã³ã°ãµã¼ãã¹ãææãããã¼ã·ãã¯ã¯ã2018å¹´12æã«ä¸æ£ã¢ã¯ã»ã¹ãåããå¤ãã®é¡§å®¢æ å ±ã第ä¸è ã«ä¾µå®³ãããå¯è½æ§ã®ããã»ãã¥ãªãã£ã¤ã³ã·ãã³ããçµé¨ãããçµæçã«æ å ±æµåºã¯ç¢ºèªãããªãã£ãããå®éã«ã¤ã³ã·ãã³ã対å¿ãçµé¨ãããã¨ã§å¤ãã®æè¨ãå¾ãã¨ãããå½æã®ç¶æ³ãªã©ãéçºé¨ æé«æè¡è²¬ä»»è ï¼CTOï¼ã®æ¡åºæ´ä¹æ°ã«èããã ã¯ã©ã¦ãã®èª²éã§æ°ä»ããç°å¤ å社ãçµé¨ããã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã¯ããµã¼ãã¹æä¾åºç¤ã¨ãã¦å©ç¨ãã¦ããAmazon Web Servicesï¼AWSï¼ã§ã®ä¸æ£ã¢ã¯ã»ã¹ãçºç«¯ã¨ãªã£ããå社ã®AWS EC2ç°å¢ã«ããã¦ä½è ããä¸æ£ã«ã¤ã³ã¹ã¿ã³ã¹ãæ§ç¯ã稼åãããä»®æ³é貨ã®çºæãè¡ã£ã¦ããããã®å½±é¿ã§
2. Shun Suzaki(æ´²å´ ä¿) Twitter:@tigerszk ITã¤ãã³ãã®åå ã»éå¬ãæ¥ã ã®èå¼±æ§æ¤è¨¼ãã©ã¤ãã¯ã¼ã¯ã¨ ãããã¨ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã Daiki Ichinose(ä¸ãç¬ å¤ªæ¨¹) Twitter:@mahoyaya Perlã好ããªã¦ã£ã¼ã¯ãã¼ãã°ãã³ã¿ã¼ã åæ¥ã¯å®¶æãµã¼ãã¹ã¨ã³ãã¥ããã£æ´»åã«å¤ããã§ããã Ken Kitahara(åå æ²) å士ï¼çå¦ï¼ãç©çå¦ã§å士å·ãåå¾ãã¦ããã2014å¹´4 æããç¸ãæç¸ããªãæ å ±ã»ãã¥ãªãã£æ¥çã§åãå§ããã ãããã¯ã¼ã¯ç³»ã®ãµã¤ãã¼æ»ææè¡ãå°éã
ã¹ãã£ã³ã¢ã³ã¹ã¿ã¼
ã¯ããã« èªåã使ã£ã¦ããAWSç°å¢ã®ã»ãã¥ãªãã£ã«åé¡ããªããã¨å¿é ã«ãªããã¨ã¯ãªãã§ããããï¼ç§ã¯ããããã¾ããããã§CIS Amazon Web Service Foundations Benchmark ã¨ããAWSã®ã»ãã¥ãªãã£ã®ã¬ã¤ãã©ã¤ã³ã«æ²¿ã£ã¦ä½¿ã£ã¦ããAWSã¢ã«ã¦ã³ãã®ã»ãã¥ãªãã£ã®ç¶æ³ããã§ãã¯ãã¦ã¿ã¾ããããã§ãã¯é ç®ã¯å ¨é¨ã§52ããã¾ããå 容ãä¸éã確èªããã¨ããç¥ããªãã£ãAWSã®ã»ãã¥ãªãã£ã®æ©è½ããã¦ãã¦ãç¥ããã¨ãã§ããè¦ãã ãã§ãã¨ã¦ãåå¼·ã«ãªãã¾ãããç°¡åã«ãã§ãã¯ããæ¹æ³ãä½µãã¦ç´¹ä»ãã¾ãã®ã§ãã²ä½¿ã£ã¦ããAWSç°å¢ã§ãã§ãã¯ãã¦ã¿ã¦ãã ããã 1 IAM 1.1 rootã¢ã«ã¦ã³ããå©ç¨ããªã rootã¢ã«ã¦ã³ãã¯å¼·åãªæ¨©éãæã¤ãããrootã¢ã«ã¦ã³ããå©ç¨ããIAMã¦ã¼ã¶ã¼ãå©ç¨ãã¦ãã ãããé常éç¨ã§rootã¢ã«ã¦ã³ããå©ç¨ããã¦ããªãã確èªã
ããã«ã¡ã¯ãåå·»ã§ãã Tenable.ioãå©ç¨ããèå¼±æ§è¨ºæã«é¢ããã¨ã³ããªã§ãã AWSã®é©æ£å©ç¨è¦ç´ã§ã¯ã許å¯ã®ãªãèå¼±æ§è¨ºæçã¯ç¦æ¢ããã¦ãããäºåã«ç³è«ãå¿ è¦ã¨ãªãã¾ããAWSã¸ç³è«ãè¡ã£ã¦ããã許å¯ã¾ã§æéããããã¾ãã®ã§ä½è£ããã£ã対å¿ãå¿ è¦ã¨ãªãã¾ãã æéããããã«èå¼±æ§è¨ºæãè¡ãããã¨æã£ãäºã¯ããã¾ãããï¼ AWS Marketplaceã«å ¬éããã¦ããNessusScannerãå©ç¨ããã°ãAWSäºåæ¿èªæ¸ã¿ã®ãããããã«èå¼±æ§è¨ºæãè¡ããã¨ãã§ãã¾ãï¼ æ¬ã¨ã³ããªã¯15åä½ã§è©¦ããã¨æãã¾ãã®ã§Tenable.ioã«è§¦ã£ããã¨ããªãæ¹ã¯ãã²ãã£ã¦ã¿ã¦ãã ããã ã¹ãã£ã³çµæã¯Tenable.ioã«ã¢ãããã¼ãããããã¡ããã確èªãããã¨ã«ãªãã¾ãã®ã§ãTenable.ioã®ã¢ã«ã¦ã³ããå¿ è¦ã«ãªãã¾ããã¢ã«ã¦ã³ãããªãå ´åã¯ãã¡ããããã©ã¤ã¢ã«ã¢ã«ã¦ã³ããä½æãã¦
Cookpad techconf 2018ã®LTã§è¬æ¼ããè³æã§ã
I was preparing some AWS Security related training. Soon, I realized that this topic is too huge to fit into my brain. So I structured my thoughts in a mind map1. Within a couple of minutes2 I came up with this: What is your first reaction? Mine was pretty much surprised: Let me summarize how AWS Security works to make sure you are not surprised one day. This post received over 200 points on Hacke
2017å¹´9æ23æ¥æ´æ° 許å¯ããã¦ãããªã½ã¼ã¹ã«ã¤ãã¦ã¢ãããã¼ãããããã¨ã確èªããã®ã§ã対象ãªã½ã¼ã¹ã«ã¤ãã¦ããæ´æ°ãã¾ãã 2018å¹´11æ07æ¥æ´æ° ããã°ãæ´æ°ãã¾ããã ã2018å¹´çãAWSã®èå¼±æ§ãã¹ããä¾µå ¥ãã¹ãã«ã¤ã㦠ã¯ãã㫠以åAWSã®ä¾µå ¥ãã¹ãã«ã¤ãã¦(Amazon EC2ã¸ã®ä¾µå ¥ãã¹ãç³è«ã«ã¤ãã¦)ãæ稿ãã¾ãããã æ°ãã«ãTotal Bandwidth (Please provide expected Gbps)*ãã®é ç®ã追å ãããã®ã§ã ä¾µå ¥ãã¹ãã«é¢ãã確èªäºé ãå 容ã«ã¤ãã¦ã¢ãããã¼ããã¾ããã ä¾µå ¥ãã¹ã AWSã§ã¯AWSç°å¢ã¸ã®ãã¾ãã¯AWSç°å¢ããã®ä¾µå ¥ãã¹ãã¨èå¼±æ§ã¹ãã£ã³ãå®æ½ããå ´åã AWSã§ç¦æ¢ããã¦ããè¡çºã¨åºå¥ããããã«äºåã«ä¾µå ¥ãã¹ãã®æ¿èªãå¾ãå¿ è¦ãããã¾ãã ä¾µå ¥ãã¹ã ç§ãã¡ã®é©æ£å©ç¨è¦ç´ã§ã¯ãç¦æ¢ããã¦ããã»ãã¥ãªã
Amazon Inspectorã触ãæ©ä¼ããã£ããããèå¼±æ§è¨ºæã«ãããAmazon Inspectorã®ä½ç½®ã¥ãã軽ãæ´çããä¸ã§ãèªåãªãã«ãã®ä½¿ãæ¹ãã¾ã¨ãã¾ããã Amazon Inspectorã¨ã¯ï¼ Amazon Inspectorã¨ã¯AWSãæä¾ããèå¼±æ§è¨ºæãè¡ããµã¼ãã¹ã§ãã¨ã¼ã¸ã§ã³ããå©ç¨ãããã©ãããã¼ã 診æã®ããã®ãµã¼ãã¹ã§ããEC2ã«å¯¾ãã¦å®æ½ãããã®ã§ææã§ããã¾ãEC2ã®ã¿ã®ãããä»ç¤¾ã¯ã©ã¦ãã®ã¤ã³ã¹ã¿ã³ã¹ããã¼ã¿ã»ã³ã¿ã¼ã«ãããµã¼ãã«ã¯å®è¡ã§ãã¾ããã ãããããµã¼ãã¹ãæ±ããããèæ¯ï¼ç§è¦ï¼ ããã¾ã§ç§è¦ã§ãããã»ãã¥ãªãã£ã¸ã®åãçµã¿ã«ã¯ã¾ãã¯ããªã¹ã¯ã®å¯è¦åããå¿ è¦ã¨è¨ããã¦ã¾ãããããã¾ã§ã¯ã¤ã³ãã©æ å½è ã¨ããã人ãã«ä¾åããå½¢ã§ãèªåãã¡ã®ãµã¼ãã¹ã§å©ç¨ãã¦ãããµã¼ãã®OSãããã«ã¦ã§ã¢ã«èå¼±æ§æç¡ã®å¯è¦åã対å¿ãè¡ããã¦ãããã¨ãå¤ãããã«æã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}