Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

No IP, No Problem - Exfiltrating Data Behind IAP

fwd:cloudsec via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Discover critical security vulnerabilities in Google Cloud's Identity-Aware Proxy (IAP) through this conference talk that exposes how misconfigurations can lead to data exfiltration even in highly secured environments. Learn about a newly identified IAP vulnerability that enables attackers to bypass network controls and extract data without sending traffic to the public internet, circumventing protections like VPC Service Controls and hardened perimeters. Explore real-world examples of dangerous IAM binding configurations, misplaced trust in user-supplied headers, and overlooked endpoints that expand attack surfaces in GCP environments. Gain deep insights into IAP's internal architecture and mechanisms, understand how subtle configuration errors can compromise supposedly secure cloud infrastructures, and develop practical detection strategies to identify these vulnerabilities. Examine the critical importance of properly defining trust boundaries in Google Cloud Platform and learn to challenge assumptions about IAP as an ultimate security gatekeeper for internal services.

Syllabus

No IP, No Problem: Exfiltrating Data Behind IAP

Taught by

fwd:cloudsec

Reviews

Start your review of No IP, No Problem - Exfiltrating Data Behind IAP

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.