Most Popular Stories
- Microsoft to challenge iCloud with Windows 8 SkyDrive
- Huddle releases private beta of new Huddle Sync service
- McAfee's SiteAdvisor plug-in causes huge performance problem, says Mozilla
- Report: iPad 3 processor is an A5X chip
- Google took steps to circumvent privacy settings for IE, Safari
- Spotlight: Samsung ships new line of rugged, waterproof memory cards
Events
- BlackBerry World – Register Now & Save!
May 1-3, 2012 — Orlando, FL - DrupalCon Denver: Drupal Means Business
March 20 - 23, 2012 — Denver, CO - BlackBerry World – Register Now & Save!
May 1-3, 2012 — Orlando, FL - SATELLLITE 2012 Conference and Exhibition
CONFERENCE: March 12 - 15, 2012; EXHIBITION: March 12 - 14, 2012
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Whitepaper: Integrated Analytics and WCM Can Improve Performance & ROI
- Enterprise Portals: Harnessing Portal Power
- The Top 4 Reasons Your Telecom Expense Management Provider Shouldn't Manage Your Wireless
- Because Hope Is Not A Strategy: Business Continuity/Disaster Recovery Planning
- Cloud Computing: Threat or opportunity for VARs and MSPs? Special focus on cloud collaboration and messaging
- Innovative Solutions for Database and DBA Management
Security flaw in cloud architectures including Amazon Web Services
Security researchers from Germany's Ruhr University have uncovered flaws in Amazon Web Services that allowed them to gain administrative rights and access user data. While the vulnerabilities in AWS have since been fixed, the researchers believe that similar problems could exist in many cloud architectures.
In a nutshell, the flaw revolves around how an XML signature-based attack can be used to manipulate SOAP messages and have the manipulated results register as authentic. A separate cross-site scripting flaw also allowed the researchers to potentially hijack an AWS session to access customer data, though not including payment information or account passwords.
According to the Rhur team, Eucalyptus, an open source solution commonly used for private cloud computing, is also vulnerable to XML rewriting attacks. Indeed, the team noted that flaws were found in "nearly every implementation," though the severity of the problem may vary depending on actual implementations.
Amazon (NASDAQ: AMZN) had been quick to rectify both problems, and gave the assurance that no customers have been infected. In a statement, the cloud computing giant wrote: "It is important to note that this potential vulnerability involved a very small percentage of all authenticated AWS API calls that use non-SSL endpoints and was not a potentially widespread vulnerability as has been reported."
You can read the full research paper here (.pdf).
For more on this story:
- check out this article at Computerworld
- check out this article at The Register
- check out this article at PCWorld
Related Articles:
SoundOff: What we've learned about the cloud in 2011
Top cloud services ranked by speed
Worst ever BlackBerry outage highlights imperfection of the cloud model
Related Stories
- Amazon Web Services adds Windows Server to free usage tier
- Hacking group releases new DDoS attack against SSL
- Microsoft issues advisory about SSL/TLS vulnerability, promises patch
- HTTPS vulnerable to man-in-the-middle attacks
- Outage hits Microsoft Office 365 customers
- Report: Improper SSL implementations are widespread
- Amazon Web Service suffers outage in Europe
- Encrypt your cloud data before it's too late
- Dropbox terms of service tweak triggers privacy scare
- Security flaws plague VMs on Amazon's cloud
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |




