Case B89D0A · Cloud · L3 Applied
Capital One 2019 Breach
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Chain: a misconfigured WAF on EC2 allowed SSRF to the metadata service, yielding creds for the role attached to that instance
- That WAF role could list and read far more S3 than it needed; the attacker listed then synced buckets (~100M US, ~6M Canada)
- Access in March 2019 went unnoticed: no alerts on the role used unusually or bulk S3 reads, despite logs recording it
- Found July 2019 via a disclosure email about a GitHub file with the attack commands and bucket list, not by monitoring
- Aftermath: $80M OCC penalty and a class-action settlement; lessons: least-privilege roles, IMDSv2, egress limits, credential anomalies
If the interviewer pushes back
- The stolen role credentials were used from outside AWS. Which policy conditions or GuardDuty findings would have contained or flagged that?
- Why did a WAF role need any S3 access, and how would you have scoped it to limit the blast radius?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.