Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

No IP, No Problem - Exfiltrating Data Behind IAP

BSidesLV via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Discover critical security vulnerabilities in Google Cloud Platform's Identity-Aware Proxy (IAP) through this 22-minute conference talk that exposes how attackers can exfiltrate data without requiring public IP addresses. Learn about dangerous misconfigurations in IAP implementations, including IAM binding issues, excessive trust in HTTP headers, and commonly overlooked endpoints that create security gaps. Explore practical demonstration techniques showing how these vulnerabilities enable unauthorized data access and exfiltration from supposedly protected cloud resources. Gain insights into effective detection strategies for identifying these security weaknesses in your own GCP environments and develop a more critical understanding of trust boundaries within Google Cloud Platform's security model.

Syllabus

- Date/Time: Tuesday, 11:00–11:20

Taught by

BSidesLV

Reviews

Start your review of No IP, No Problem - Exfiltrating Data Behind IAP

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.