AWS Virtual Machines Deployed With Security Holes

German researchers uncovered multiple security problems within Amazon’s cloud-computing services caused by customers ignoring or forgetting security tips.

Researchers looked at some 1,100 Amazon Machine Images and found the majority of them contained security keys used to authenticate with other services and servers.

“They [customers] just forgot to remove their API keys from machines before publishing,” Thomas Schneider, a post-doctoral researcher in the System Security Lab of Technische Universitat Darmstadt, wrote in a paper.

A Change Of Key

Amazon Machine Images are preconfigured operating systems and application software used to create virtual machines. Anyone can create these images and allow others to use them when rolling out their own virtual infrastructure. Anyone with an Amazon Web Services account can browse through the public AMIs.

Researchers found that the private keys used to authenticate with Amazon services such as Elastic Compute Cloud (EC2) or Simple Storage Service (S3) were published in those AMIs. About a third of the studied AMIs also contained Secure Shell (SSH) host keys or user keys. SSH is a common tool used to log into and manage a virtual machine and the keys authenticate the user onto the server.

Unless the host key is removed and replaced from the AMI, every virtual machine created from that image will use the same key, creating the possibility of a malicious user impersonating the server and launching phishing attacks. SSH user keys are also used for root-privileged log-ins. With the user keys, the interloper can log in using super-user privileges unless the owner discovers and closes the “backdoor”, researchers said.

With the authentication keys for EC2 and S3, any third-party miscreant can connect and create “virtual infrastructure worth several thousands of dollars per day at the expense” of the original customer, the researchers found.

The AMIs also contained valid SSL (Secure Sockets Layer) certificates and their private keys, which would allow attackers to impersonate the servers. The researchers also uncovered source code for unpublished software products, passwords and personal identifiable information such as pictures and notes.

Ignoring The Guidelines

Amazon Web Services is very easy to use, and customers can easily purchase and roll out servers and storage services. It is also so easy to use that users are creating virtual machines without following Amazon’s recommendations on security and implementation, according to Schneider.

“These guidelines are very detailed,” Schneider said.

Security experts have paid close attention to underlying cloud infrastructures and providers, but have underestimated or ignored the “threats caused by the cloud customers when constructing services”, the researchers said. Flawed configurations meant anyone could harvest critical data such as passwords and cryptographic keys and certificates from virtual machines. Attackers would be able to “operate criminal virtual infrastructures, manipulate Web services and circumvent security mechanisms”, the researchers wrote.

Customers can endanger themselves and other users with the “careless and error-prone manner” in which AMIs are handled and deployed, the researchers said.

Once the researchers uncovered the problem, they contacted Amazon Web Services with their findings at the end of April. Amazon notified those account holders of the security issues, Schneider said.

The study was done by the Centre for Advanced Security Research Darmstadt and the Fraunhofer Institute for Security in Information Technology in Darmstadt, Germany.

Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Share
Published by
Fahmida Y Rashid eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved.

Recent Posts

France Fines Apple Over Ad Tracking Feature

Apple fined 150m euros over App Tracking Transparency feature that it says abuses Apple's market…

13 hours ago

OpenAI To Release Open-Weight AI Model

OpenAI to release customisable open-weight model in coming months as it faces pressure from open-source…

13 hours ago

Samsung AI Fridge Creates Shopping Lists, Adjusts AC

Samsung's Bespoke AI-powered fridge monitors food to create shopping lists, displays TikTok videos, locates misplaced…

14 hours ago

Huawei Consumer Revenues Surge Amidst Smartphone Comeback

Huawei sees 38 percent jump in consumer revenues as its smartphone comeback continues to gather…

14 hours ago

China Approves First ‘Flying Car’ Licences

In world-first, China approves commercial flights for EHang autonomous passenger drone, paving way for imminent…

15 hours ago

Microsoft Shutters Shanghai Lab In Latest China Pullback

Microsoft closes down IoT and AI lab it operated in Shanghai tech district in latest…

15 hours ago