Open cardosec

Case B89D0A · Cloud · L3 Applied

Capital One 2019 Breach

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Chain: a misconfigured WAF on EC2 allowed SSRF to the metadata service, yielding creds for the role attached to that instance
  2. That WAF role could list and read far more S3 than it needed; the attacker listed then synced buckets (~100M US, ~6M Canada)
  3. Access in March 2019 went unnoticed: no alerts on the role used unusually or bulk S3 reads, despite logs recording it
  4. Found July 2019 via a disclosure email about a GitHub file with the attack commands and bucket list, not by monitoring
  5. Aftermath: $80M OCC penalty and a class-action settlement; lessons: least-privilege roles, IMDSv2, egress limits, credential anomalies

If the interviewer pushes back

  • The stolen role credentials were used from outside AWS. Which policy conditions or GuardDuty findings would have contained or flagged that?
  • Why did a WAF role need any S3 access, and how would you have scoped it to limit the blast radius?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.