> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Blast from the past: Cross Site Scripting on the AWS Console

[SOURCE] Embrace The Red [DATE: 01/07/2020 10:30] [LANGUAGE: EN]
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program Bad news: AWS is out of scope! When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console. This post is a write up on how I found the XSS back then, techniques I used and how they evolved over the years and Amazon’s response. AWS Console and Cross Site Scripting The story is that I had just created an AWS account and started using the service.
[messages.read_original_source] →