Overview
Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Discover a critical security vulnerability in Amazon ECS through this conference talk that exposes how attackers can hijack IAM privileges across container boundaries. Learn about the technical exploitation of an undocumented Amazon ECS protocol that enables low-privileged roles running on EC2 instances to steal IAM credentials from higher-privileged containers sharing the same infrastructure. Explore the breakdown of security boundaries in modern cloud environments and understand how shared infrastructure in containerized deployments creates unexpected attack vectors. Examine the detailed technical mechanics behind this privilege escalation attack and gain insights into the underlying vulnerabilities in Amazon's container orchestration service. Master essential security best practices for preventing role co-location risks, including strategies for proper workload isolation and deployment patterns that prevent privilege hijacking scenarios in your cloud infrastructure.
Syllabus
ECS-cape – Hijacking IAM Privileges in Amazon ECS
Taught by
fwd:cloudsec