October 31, 2011
"In this paper, they provide a security analysis pertaining to the control interfaces of a large Public Cloud (Amazon) and a widely used Private Cloud software (Eucalyptus). Their research results are alarming: in regards to the Amazon EC2 and S3 services, the control interfaces could be compromised via the novel signature wrapping and advanced XSS techniques. Similarly, the Eucalyptus control interfaces were vulnerable to classical signature wrapping attacks, and had nearly no protection against XSS."
Read more from [marcoramilli]
Labels: cloud security, signature wrapping attacks, XSS
This entry was posted
on October 31, 2011 at 04:20.
You can skip to the end and leave a response.