Tag: ECScape Flaw

Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft
News

Researchers Uncover ECScape Flaw in Amazon ECS Enabling Cross-Task Credential Theft

Researchers studying cybersecurity have shown that Amazon Elastic Container Service (ECS) has a "end-to-end privilege escalation chain" that an attacker might use to move laterally, gain access to private information, and take over the cloud environment. Sweet Security researcher Naor Haziz has dubbed the attack method ECScape. He presented the results today at the Black Hat USA security conference in Las Vegas. In a report provided to The Hacker News, Haziz stated, "We discovered a method to misuse an undocumented ECS internal protocol in order to obtain AWS credentials associated with other ECS tasks on the same EC2 instance." The permissions of a higher-privileged container running on the same host can be obtained by a malicious container with a low-privileged IAM [Identity and A...