Code Monkey home page Code Monkey logo

unmasking-the-subnet's Introduction

Unmasking the Subnet: Lookalike IP Ranges in Cloud Environments

This repository contains all materials associated with the talk "Unmasking the Subnet: Lookalike IP Ranges in Cloud Environments" presented by Asaf Aprozper at fwd:cloudsec 2023.

   __  __                           __   _                ________            _____       __               __ 
  / / / /___  ____ ___  ____ ______/ /__(_)___  ____ _   /_  __/ /_  ___     / ___/__  __/ /_  ____  ___  / /_
 / / / / __ \/ __ `__ \/ __ `/ ___/ //_/ / __ \/ __ `/    / / / __ \/ _ \    \__ \/ / / / __ \/ __ \/ _ \/ __/
/ /_/ / / / / / / / / / /_/ (__  ) ,< / / / / / /_/ /    / / / / / /  __/   ___/ / /_/ / /_/ / / / /  __/ /_  
\____/_/ /_/_/ /_/ /_/\__,_/____/_/|_/_/_/ /_/\__, /    /_/ /_/ /_/\___/   /____/\__,_/_.___/_/ /_/\___/\__/  
                                             /____/                                                                                            

About the Talk

In the evolving landscape of cloud computing, safeguarding networks from unauthorized access remains crucial. This talk explores a less-discussed risk factor โ€“ the use of lookalike private IP ranges. The discussion unfolds our investigation that revealed cloud users' erroneous configuration of Security Groups and VPCs with IP ranges, which they presumed to be internal but were, in fact, publicly exposed to US cellular networks and potentially to malicious actors. The talk not only highlights the security risks associated with lookalike IP addresses in cloud environments but also offers practical hunting rules to mitigate such misconfigurations.

Repository Contents

  • Proxy IP Unmasker/: Python script that scans IPv4 ranges and "unmasks" those only accessible from proxy IP addresses.
  • SG Unmasker/: Python script that scans your AWS security groups under a sepcific regsion after misconfigured ingress rules with lookalike private IP ranges
  • Rules/: SIEM Hunting rules triggered by the creation/modification of security groups\FW Rules contains ingress lookalike internal IP ranges of AT&T and T-Mobile.
  • Presentation/: The slide deck from the talk.

Please use this repository responsibly, as it is intended for educational purposes only.

References

About the Author

Asaf Aprozper (3pun0x) - Creator - Twitter - LinkedIn

Contributing

Contributions are more than welcome! Feel free to fork the repository and submit pull requests. For significant changes, please open an issue first to discuss what you would like to modify.

License

License

unmasking-the-subnet's People

Contributors

3pun0x avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar

Watchers

 avatar

Forkers

danigoland

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.