BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: One Click\, Six Services: Abusing The Dangerous Mult
 i-service\n   Orchestration Pattern\n   When: Saturday\, Aug 10\, 11:50 - 
 12:15 PDT\n   Where: LVCC West/Floor 1/Hall 2/HW2-09-01 - [1]Map\n\n   Des
 cription:\n\n   Cloud providers build their services a little like Jenga t
 owers. They\n   use their core services as the foundation of more popular\
 n   customer-facing offerings. You may think you’re just creating a GCP\
 n   cloud function in an empty account. In reality\, with one click\,\n   
 you’re creating resources in six different services: a Cloud Build\n   i
 nstance\, a Storage Bucket\, an Artifact Registry or a Container\n   Regis
 try\, and possibly a Cloud Run instance and Eventarc triggers. The\n   sec
 urity of the entire stack is only as strong as the weakest link.\n\n   By 
 looking at the entire stack\, we can find privilege escalation\n   techniq
 ues and even vulnerabilities that are hidden behind the stack.\n   In my r
 esearch\, I was able to find a novel privilege escalation\n   vulnerabilit
 y and several privilege escalation techniques in GCP.\n\n   The talk will 
 showcase a key concept\, sometimes not discussed enough:\n   cloud service
 s are built on top of each other\, and one click in the\n   console can ca
 use many things to happen behind the scenes. More\n   services mean more r
 isks and a larger attack surface.\n\n   The next part will dive deep into 
 the vulnerable GCP cloud functions\n   deployment flow. I will showcase th
 e vulnerability I found in this\n   flow\, which enables an attacker to ru
 n code as the default Cloud Build\n   service account by exploiting the de
 ployment flow and the flawed trust\n   between services resulting in a lar
 ge fix and change in GCP IAM and\n   Cloud Functions. This would grant an 
 attacker high privileges to key\n   services such as Storage\, Artifact Re
 gistry\, and Cloud Build.\n\n   However\, this talk is about more than jus
 t a vulnerability. By\n   understanding cross-service dependency\, we can 
 reveal a broad attack\n   surface for many possible privilege escalation v
 ectors between\n   services. I will demo a simple tool I wrote to find the
  hidden APIs\n   that are called by the CSP when performing an action.\n\n
    By the end of this talk\, the audience will learn the dangers of\n   tr
 eating cloud services like a black box. The talk explains the hidden\n   d
 eployment flow behind one important stack\, and provides the tools to\n   
 uncover the risks of many more.\n\n   SpeakerBio:  Liv Matan\n\n   Liv Mat
 an (@terminatorLM) is a Senior Security Researcher at Tenable\,\n   where 
 he specializes in application and web security. He previously\n   worked a
 s a Security Researcher at Ermetic and served in the Israeli\n   Intellige
 nce Corps as a Software Developer. As a bug bounty hunter\,\n   Liv has fo
 und several vulnerabilities in popular software platforms\,\n   such as Az
 ure\, Google Cloud\, AWS\, Facebook and Gitlab\, was recognized\n   by Mic
 rosoft as a Most Valuable Researcher\, and has presented at\n   conference
 s such as DEF CON Cloud Village and fwd:cloudsec. Liv\n   studied computer
  science at the Weizmann Institute of Science\, in\n   Israel. In his free
  time\, he boxes\, lifts weights and plays Capture\n   the Flag (CTF).\n\n
    '\n\n   1. #LVCCW_Level1_Hall2\n\n\n
DTEND:20240810T191500Z
DTSTART:20240810T185000Z
LOCATION:CLV - LVCC West/Floor 1/Hall 2/HW2-09-01
SUMMARY:One Click\, Six Services: Abusing The Dangerous Multi-service Orche
 stration Pattern
END:VEVENT
END:VCALENDAR
