SlideShare a Scribd company logo
Owning a company through
their logs
Aseem Shrey
Security Engineer ( Grofers )
@AseemShrey
Can logs be that useful ?
How did I get here ?
● Passive Reconnaissance - Shodan
● Searching for Jenkins and Sonarqube open instances
Owning a company through their logs
Owning a company through their logs
Automate Them All
Leaking Secrets
Slack Channels --> AWS creds
● slack channel list
● aws s3api list-buckets — query “Buckets[].Name”
Key Takeaways
● Know your boundaries : If you think that the data you’ve got access wasn’t meant to be
accessible to you and was meant to be private, STOP. Take written permission from the company
before testing any further.
● Automate them all : Let machines take over ( The mundane tasks only ). While I had
automated the screenshot part, I was also checking for RCE on Jenkins on these instances ( i.e.
Jenkins instances with open Script Console and I did get quite a few )
● Don’t presume anything : Now, usually Jenkins replaces secrets with asterisks but it can’t
mask the tool output and as in this case the zookeeper was leaking the credentials.
● No secret sauce : Bugs are simple, persistence is the key.
The Blogpost
Owning a company through their logs

More Related Content

PDF
Bettercap
Rajivarnan (Rajiv)
 
PPTX
Spark intro by Adform Research
Vasil Remeniuk
 
PPTX
Testing in Scala. Adform Research
Vasil Remeniuk
 
PPTX
Sinatra
techwhizbang
 
PPTX
Javasession5
Rajeev Kumar
 
PDF
Security Testing with OWASP ZAP in CI/CD - Simon Bennetts - Codemotion Amster...
Codemotion
 
PDF
Auto-testing production CQ instances with Muppet
connectwebex
 
Spark intro by Adform Research
Vasil Remeniuk
 
Testing in Scala. Adform Research
Vasil Remeniuk
 
Sinatra
techwhizbang
 
Javasession5
Rajeev Kumar
 
Security Testing with OWASP ZAP in CI/CD - Simon Bennetts - Codemotion Amster...
Codemotion
 
Auto-testing production CQ instances with Muppet
connectwebex
 

What's hot (6)

PDF
Advanced Jasmine - Front-End JavaScript Unit Testing
Lars Thorup
 
PPTX
Jasmine with JS-Test-Driver
Devesh Chanchlani
 
PPT
Testing in AngularJS
Peter Drinnan
 
PPTX
Unit testing in JavaScript with Jasmine and Karma
Andrey Kolodnitsky
 
PDF
Re invent 2018 - The Evolution of AircraftML
jerryhargrove
 
PDF
Maintaining Your Tests At Scale
Trent Willis
 
Advanced Jasmine - Front-End JavaScript Unit Testing
Lars Thorup
 
Jasmine with JS-Test-Driver
Devesh Chanchlani
 
Testing in AngularJS
Peter Drinnan
 
Unit testing in JavaScript with Jasmine and Karma
Andrey Kolodnitsky
 
Re invent 2018 - The Evolution of AircraftML
jerryhargrove
 
Maintaining Your Tests At Scale
Trent Willis
 
Ad

Similar to Owning a company through their logs (20)

PPTX
Why internal pen tests are still fun
pyschedelicsupernova
 
PPTX
DevSecCon Tel Aviv 2018 - Integrated Security Testing by Morgan Roman
DevSecCon
 
PDF
Safe and Fast Automation on AWS for Fun and Profit
Raghavendra Prabhu
 
PDF
AWS Cloud Account Hacked
Ali Raza
 
PDF
Sensu @ Yelp!: A Guided Tour
Kyle Anderson
 
ODP
2017 Codemotion OWASP ZAP in CI/CD
Simon Bennetts
 
PDF
Secret Management Journey - Here Be Dragons aka Secret Dragons
Michael Man
 
ODP
Automating OWASP ZAP - DevCSecCon talk
Simon Bennetts
 
ODP
Simon Bennetts - Automating ZAP
DevSecCon
 
PPTX
The basics of hacking and penetration testing 이제 시작이야 해킹과 침투 테스트 kenneth.s.kwon
Kenneth Kwon
 
PPTX
Secrets management in the cloud
Evan J Johnson (Not a CISSP)
 
PPTX
Grabbing Forensic Images from EC2/Rackspace
JP Bourget
 
PDF
The Oracle Awakens: Demystifying Privilege Escalation in the cloud
Cloud Village
 
PPTX
It's 10pm, Do You Know Where Your Access Keys Are?
Ken Johnson
 
PDF
Shmoocon 2015 - httpscreenshot
jstnkndy
 
PPTX
Attacking aws workshops - teaser
Pawel Rzepa
 
PDF
Windows logging workshop - BSides Austin 2014
Michael Gough
 
PDF
SplunkLive! Washington DC May 2013 - Splunk Security Workshop
Splunk
 
PDF
Hunting for the secrets in a cloud forest
Pawel Rzepa
 
PDF
CONFidence 2018: Hunting for the secrets in a cloud forest (Paweł Rzepa)
PROIDEA
 
Why internal pen tests are still fun
pyschedelicsupernova
 
DevSecCon Tel Aviv 2018 - Integrated Security Testing by Morgan Roman
DevSecCon
 
Safe and Fast Automation on AWS for Fun and Profit
Raghavendra Prabhu
 
AWS Cloud Account Hacked
Ali Raza
 
Sensu @ Yelp!: A Guided Tour
Kyle Anderson
 
2017 Codemotion OWASP ZAP in CI/CD
Simon Bennetts
 
Secret Management Journey - Here Be Dragons aka Secret Dragons
Michael Man
 
Automating OWASP ZAP - DevCSecCon talk
Simon Bennetts
 
Simon Bennetts - Automating ZAP
DevSecCon
 
The basics of hacking and penetration testing 이제 시작이야 해킹과 침투 테스트 kenneth.s.kwon
Kenneth Kwon
 
Secrets management in the cloud
Evan J Johnson (Not a CISSP)
 
Grabbing Forensic Images from EC2/Rackspace
JP Bourget
 
The Oracle Awakens: Demystifying Privilege Escalation in the cloud
Cloud Village
 
It's 10pm, Do You Know Where Your Access Keys Are?
Ken Johnson
 
Shmoocon 2015 - httpscreenshot
jstnkndy
 
Attacking aws workshops - teaser
Pawel Rzepa
 
Windows logging workshop - BSides Austin 2014
Michael Gough
 
SplunkLive! Washington DC May 2013 - Splunk Security Workshop
Splunk
 
Hunting for the secrets in a cloud forest
Pawel Rzepa
 
CONFidence 2018: Hunting for the secrets in a cloud forest (Paweł Rzepa)
PROIDEA
 
Ad

More from n|u - The Open Security Community (20)

PDF
Hardware security testing 101 (Null - Delhi Chapter)
n|u - The Open Security Community
 
PPTX
SSRF exploit the trust relationship
n|u - The Open Security Community
 
PDF
Metasploit primary
n|u - The Open Security Community
 
PDF
Api security-testing
n|u - The Open Security Community
 
PDF
Introduction to TLS 1.3
n|u - The Open Security Community
 
PDF
Gibson 101 -quick_introduction_to_hacking_mainframes_in_2020_null_infosec_gir...
n|u - The Open Security Community
 
PDF
Talking About SSRF,CRLF
n|u - The Open Security Community
 
PPTX
Building active directory lab for red teaming
n|u - The Open Security Community
 
PPTX
Introduction to shodan
n|u - The Open Security Community
 
PDF
Detecting persistence in windows
n|u - The Open Security Community
 
PPTX
Frida - Objection Tool Usage
n|u - The Open Security Community
 
PDF
OSQuery - Monitoring System Process
n|u - The Open Security Community
 
PDF
DevSecOps Jenkins Pipeline -Security
n|u - The Open Security Community
 
PDF
Extensible markup language attacks
n|u - The Open Security Community
 
PPTX
Linux for hackers
n|u - The Open Security Community
 
PDF
Android Pentesting
n|u - The Open Security Community
 
PDF
News bytes null 200314121904
n|u - The Open Security Community
 
Hardware security testing 101 (Null - Delhi Chapter)
n|u - The Open Security Community
 
SSRF exploit the trust relationship
n|u - The Open Security Community
 
Api security-testing
n|u - The Open Security Community
 
Introduction to TLS 1.3
n|u - The Open Security Community
 
Gibson 101 -quick_introduction_to_hacking_mainframes_in_2020_null_infosec_gir...
n|u - The Open Security Community
 
Talking About SSRF,CRLF
n|u - The Open Security Community
 
Building active directory lab for red teaming
n|u - The Open Security Community
 
Introduction to shodan
n|u - The Open Security Community
 
Detecting persistence in windows
n|u - The Open Security Community
 
Frida - Objection Tool Usage
n|u - The Open Security Community
 
OSQuery - Monitoring System Process
n|u - The Open Security Community
 
DevSecOps Jenkins Pipeline -Security
n|u - The Open Security Community
 
Extensible markup language attacks
n|u - The Open Security Community
 
News bytes null 200314121904
n|u - The Open Security Community
 

Recently uploaded (20)

PPTX
HEALTH CARE DELIVERY SYSTEM - UNIT 2 - GNM 3RD YEAR.pptx
Priyanshu Anand
 
PPTX
How to Apply for a Job From Odoo 18 Website
Celine George
 
PPTX
HISTORY COLLECTION FOR PSYCHIATRIC PATIENTS.pptx
PoojaSen20
 
PPTX
Basics and rules of probability with real-life uses
ravatkaran694
 
PPTX
Information Texts_Infographic on Forgetting Curve.pptx
Tata Sevilla
 
PPTX
How to Track Skills & Contracts Using Odoo 18 Employee
Celine George
 
PPTX
Care of patients with elImination deviation.pptx
AneetaSharma15
 
PPTX
Kanban Cards _ Mass Action in Odoo 18.2 - Odoo Slides
Celine George
 
PDF
Module 2: Public Health History [Tutorial Slides]
JonathanHallett4
 
PPTX
CONCEPT OF CHILD CARE. pptx
AneetaSharma15
 
DOCX
Unit 5: Speech-language and swallowing disorders
JELLA VISHNU DURGA PRASAD
 
DOCX
Modul Ajar Deep Learning Bahasa Inggris Kelas 11 Terbaru 2025
wahyurestu63
 
DOCX
SAROCES Action-Plan FOR ARAL PROGRAM IN DEPED
Levenmartlacuna1
 
PPTX
Dakar Framework Education For All- 2000(Act)
santoshmohalik1
 
PDF
The Minister of Tourism, Culture and Creative Arts, Abla Dzifa Gomashie has e...
nservice241
 
PDF
RA 12028_ARAL_Orientation_Day-2-Sessions_v2.pdf
Seven De Los Reyes
 
PPTX
Cleaning Validation Ppt Pharmaceutical validation
Ms. Ashatai Patil
 
PPTX
How to Close Subscription in Odoo 18 - Odoo Slides
Celine George
 
PPTX
Applications of matrices In Real Life_20250724_091307_0000.pptx
gehlotkrish03
 
PPTX
Python-Application-in-Drug-Design by R D Jawarkar.pptx
Rahul Jawarkar
 
HEALTH CARE DELIVERY SYSTEM - UNIT 2 - GNM 3RD YEAR.pptx
Priyanshu Anand
 
How to Apply for a Job From Odoo 18 Website
Celine George
 
HISTORY COLLECTION FOR PSYCHIATRIC PATIENTS.pptx
PoojaSen20
 
Basics and rules of probability with real-life uses
ravatkaran694
 
Information Texts_Infographic on Forgetting Curve.pptx
Tata Sevilla
 
How to Track Skills & Contracts Using Odoo 18 Employee
Celine George
 
Care of patients with elImination deviation.pptx
AneetaSharma15
 
Kanban Cards _ Mass Action in Odoo 18.2 - Odoo Slides
Celine George
 
Module 2: Public Health History [Tutorial Slides]
JonathanHallett4
 
CONCEPT OF CHILD CARE. pptx
AneetaSharma15
 
Unit 5: Speech-language and swallowing disorders
JELLA VISHNU DURGA PRASAD
 
Modul Ajar Deep Learning Bahasa Inggris Kelas 11 Terbaru 2025
wahyurestu63
 
SAROCES Action-Plan FOR ARAL PROGRAM IN DEPED
Levenmartlacuna1
 
Dakar Framework Education For All- 2000(Act)
santoshmohalik1
 
The Minister of Tourism, Culture and Creative Arts, Abla Dzifa Gomashie has e...
nservice241
 
RA 12028_ARAL_Orientation_Day-2-Sessions_v2.pdf
Seven De Los Reyes
 
Cleaning Validation Ppt Pharmaceutical validation
Ms. Ashatai Patil
 
How to Close Subscription in Odoo 18 - Odoo Slides
Celine George
 
Applications of matrices In Real Life_20250724_091307_0000.pptx
gehlotkrish03
 
Python-Application-in-Drug-Design by R D Jawarkar.pptx
Rahul Jawarkar
 

Owning a company through their logs

  • 1. Owning a company through their logs Aseem Shrey Security Engineer ( Grofers ) @AseemShrey
  • 2. Can logs be that useful ?
  • 3. How did I get here ? ● Passive Reconnaissance - Shodan ● Searching for Jenkins and Sonarqube open instances
  • 8. Slack Channels --> AWS creds ● slack channel list ● aws s3api list-buckets — query “Buckets[].Name”
  • 9. Key Takeaways ● Know your boundaries : If you think that the data you’ve got access wasn’t meant to be accessible to you and was meant to be private, STOP. Take written permission from the company before testing any further. ● Automate them all : Let machines take over ( The mundane tasks only ). While I had automated the screenshot part, I was also checking for RCE on Jenkins on these instances ( i.e. Jenkins instances with open Script Console and I did get quite a few ) ● Don’t presume anything : Now, usually Jenkins replaces secrets with asterisks but it can’t mask the tool output and as in this case the zookeeper was leaking the credentials. ● No secret sauce : Bugs are simple, persistence is the key.