YouTube2Text

#NahamCon2022EU: Hunting for Amazon Cognito Security Misconfigurations by@yassineaboukir — Transcript

by NahamSec · 3,991 words · 608 segments · language en · Watch on YouTube

Full transcript

  1. 0:00hello everyone uh
  2. 0:03thank you so much for tuning in uh we're
  3. 0:05going to talk about ewe's Cognito as a
  4. 0:10solution for authentication and
  5. 0:12authorization then we're going to mainly
  6. 0:14go over a few common security
  7. 0:16misconfigurations that can affect its
  8. 0:18implementation
  9. 0:19I've chosen this topic because I've seen
  10. 0:22how easier it is to misconfigure it as
  11. 0:24well as the fact that a lot of people
  12. 0:26especially about hunters I think it's
  13. 0:29difficult to test whereas it really is
  14. 0:31not as long as you just understands how
  15. 0:34it works
  16. 0:36before we get into it let me introduce
  17. 0:38myself for those who do not know me uh
  18. 0:41my name is Yasin abukir I'm originally
  19. 0:43from Morocco based in France uh I've got
  20. 0:47a decade of experience in application
  21. 0:49security Consulting I work with
  22. 0:52companies that provide them with
  23. 0:53painters security assessments Services
  24. 0:56uh and that in similar regards I this
  25. 1:00year I joined hack one paint this
  26. 1:02program and I've been working with their
  27. 1:03clients as well so I've been doing
  28. 1:05background names for a very long time
  29. 1:07probably since late 2013 early 2014 to
  30. 1:11be accurate I mainly hack on hack one
  31. 1:14platform where I'm currently ranking in
  32. 1:16the top 20.
  33. 1:17so this year I've been fortunate I
  34. 1:20earned the most valuable hacker the
  35. 1:22image title and the first place at a
  36. 1:25live hacking event that took place in
  37. 1:27Denver
  38. 1:28as you can see in the picture in the
  39. 1:30right that's me holding the Bell looking
  40. 1:32like a UFC fighter there
  41. 1:35uh from 2017 to 2019 I had the chance to
  42. 1:39work for hacker one as a part of the
  43. 1:41triage team it was a great experience
  44. 1:43and I also love traveling and been doing
  45. 1:46it for a couple of years now as a
  46. 1:48digital Nomad just hacking from
  47. 1:50different places
  48. 1:52oh yeah that's it so let's get into it
  49. 1:54introduction to ew's Cognito uh if
  50. 1:57you've got any developer background you
  51. 2:00know that user authentication and
  52. 2:01authorization can be quite challenging
  53. 2:04when you're building a web and mobile
  54. 2:06app
  55. 2:06so the challenges like include handling
  56. 2:09just user data passwords token based
  57. 2:12authentication and managing permissions
  58. 2:15uh scalability Federation
  59. 2:18Etc so it is pretty easy to mix things
  60. 2:21up especially with on indications which
  61. 2:23is quite sensitive
  62. 2:25so Amazon Cognito offers like a scalable
  63. 2:29and complete solution to add a sign up
  64. 2:32and assigning features to your
  65. 2:34application it provides identity
  66. 2:37Federation makes it and makes just
  67. 2:40implementing security easier as long as
  68. 2:43you're just careful with how you're
  69. 2:45configuring it
  70. 2:47so uh Cognito allows not only managing
  71. 2:51authentication but it also provides a
  72. 2:54way to manage authorization user
  73. 2:57permissions which are usually time and
  74. 3:00resources consuming to properly build so
  75. 3:04when we talk about Cognito there are two
  76. 3:07main components on say concepts to
  77. 3:10distinguish
  78. 3:11first one is the user poll so when
  79. 3:14you're creating
  80. 3:15um when you're setting up cognitively
  81. 3:17you create the user pool and the user
  82. 3:20pool here allows authentication
  83. 3:21basically sign in and sign up and then
  84. 3:25we have the identity pool uh it refers
  85. 3:29it is used for authorization to allow
  86. 3:32users to use various AWS resources such
  87. 3:36as Amazon dynamodb Amazon S3 API Gateway
  88. 3:41Etc so these are the two main Concepts
  89. 3:44to remember
  90. 3:46this is a the architectural diagram that
  91. 3:50reflects a high level authentication and
  92. 3:52authorization flow uh so basically you
  93. 3:56have the user uh that authenticates to
  94. 3:59their account uh so when they're
  95. 4:02authenticated to their account they're
  96. 4:04checked against a user pool here and
  97. 4:07then the user poll will generate and
  98. 4:09return three GWT tokens uh ID access
  99. 4:14refresh token the ID token the access
  100. 4:17token and the refresh token and then the
  101. 4:21ID token is passed to the identity pool
  102. 4:24the user then will receive a temporary
  103. 4:27credentials with permissions that are
  104. 4:30based on the EM role that was mapped to
  105. 4:34the group that the user belongs to so
  106. 4:36the user can then make calls to various
  107. 4:38ew Services based on their role
  108. 4:41permissions assigned to their
  109. 4:43credentials in this case they can't
  110. 4:45access the dynamodp with the AWS
  111. 4:48credentials as you can see there
  112. 4:51uh all right how the question is how you
  113. 4:55can tell uh if an application is
  114. 4:57actually using Amazon Cognito so uh when
  115. 5:01you're doing a testing it's pretty easy
  116. 5:03like if you're using the the web proxy
  117. 5:07for example burp Suite you can just see
  118. 5:09that there are some API calls to Cognito
  119. 5:12endpoint here
  120. 5:14there are two different ones the yellow
  121. 5:16one is the request the is being made or
  122. 5:20being sent at user pull as we mentioned
  123. 5:22before when you're authenticating to
  124. 5:24your account the green one is sent after
  125. 5:27authentication to Identity pull a to
  126. 5:31exchange basically to exchange the ID
  127. 5:32token into a temporary WS credential as
  128. 5:36we previews previously mentioned in the
  129. 5:38diagram earlier so I've been personally
  130. 5:41playing with ews cognitive and exploring
  131. 5:43very security configurations in the
  132. 5:45console and I've concluded that it's
  133. 5:47quite far easier to mix things up as
  134. 5:49there are too many features and security
  135. 5:51configurations that could confuse any
  136. 5:54developer uh I've also came across a lot
  137. 5:59of these security misconfigurations both
  138. 6:02while doing back downies and penetration
  139. 6:04distance so they're actually very common
  140. 6:05to find
  141. 6:07oh okay we're gonna start with the first
  142. 6:09one uh the very first security
  143. 6:11misconfiguration is when the temporary
  144. 6:13AWS credentials are over permissive
  145. 6:17liberal credentials in a sense that the
  146. 6:21unintentionally allow access to or net
  147. 6:24to net they give you access to or
  148. 6:26manipulate other sensitive ewas services
  149. 6:31this is especially bad when
  150. 6:34unauthenticated roles are enabled as
  151. 6:36anyone without having an access to an
  152. 6:39account could generate these temporary
  153. 6:41credentials and just gain unauthorized
  154. 6:44access to these ew services
  155. 6:47so assuming we're not authenticated and
  156. 6:49we do not have access to an account
  157. 6:52there is a huge chance unauthenticated
  158. 6:55roles are enabled in the console by the
  159. 6:58developer so we basically just need to
  160. 7:00find the identity poll ID and AWS region
  161. 7:04which most
  162. 7:06likely are like over 80 percent of the
  163. 7:09time they're just hard coded somewhere
  164. 7:10in the source code or in a JS file
  165. 7:13so this is the example here as you can
  166. 7:15see below of a tech Bounty Target I was
  167. 7:17hacking on and I was able to find these
  168. 7:19pieces of information in a JS file that
  169. 7:22was being loaded by the app so it is
  170. 7:25mainly the user polidy the client ID the
  171. 7:29region and the identity pool ID the
  172. 7:32latter is what we're actually interested
  173. 7:33in and
  174. 7:36so you can just use burp Suite to search
  175. 7:38for the following keywords in order to
  176. 7:40find the identity pool ID but remember
  177. 7:44that the disclosure of this ID
  178. 7:47is not necessarily an issue or a
  179. 7:49security misconfiguration as long as the
  180. 7:51backend is properly configured right
  181. 7:55okay so actually I find the identity ID
  182. 7:58in the JS file or in the source code you
  183. 8:02can use or download the ews client which
  184. 8:05is widely used and just configure it
  185. 8:07then you can simply run the command the
  186. 8:10AWS command as you can see there in the
  187. 8:12green with the replacing the pull
  188. 8:16replacing the pull identity ID and the
  189. 8:18region so after you execute the command
  190. 8:21it will generate an identity ID this is
  191. 8:24different from the pull identity ID just
  192. 8:26the same name so it will generate an
  193. 8:28identity ID that you can see in a
  194. 8:31screenshot there
  195. 8:32and then you'll just have to copy the
  196. 8:35identity ID that was generated and
  197. 8:38execute the next command here in the
  198. 8:40green and this will generate temporary
  199. 8:43AWS credentials for you so this will
  200. 8:46generate an access key ID the secret key
  201. 8:49and decision token
  202. 8:51now we will check if these credentials
  203. 8:55the generated credentials for this an
  204. 8:57authenticator will have any liberal
  205. 8:59permissions that would allow further
  206. 9:02access to the app or to the their AWS
  207. 9:05Services there are mainly two tools that
  208. 9:08I recommend and I use the first one is
  209. 9:11enumerate aeon this is pretty this is
  210. 9:14this one is pretty easy to use and quite
  211. 9:16minimalistic as it allows enumerating
  212. 9:18these permissions uh there is also a
  213. 9:21comprehensive one called Scout Suite
  214. 9:23this one is more comprehensive and does
  215. 9:25the same thing uh you can check their
  216. 9:27GitHub represent rate on how you can
  217. 9:29configure it but in this screenshot I
  218. 9:32mainly used enumerate em and managed to
  219. 9:35enumerate some permissions uh associated
  220. 9:38with the credential that we generated
  221. 9:40but in this screenshot nothing really
  222. 9:43was interesting I don't have any
  223. 9:45screenshots so
  224. 9:47uh
  225. 9:48like sensitive services that I've had
  226. 9:50successfully unfortunately but as you
  227. 9:52can see the the idea is the same we
  228. 9:55enumerated some permissions like the git
  229. 9:57color identity this one is now
  230. 9:59interesting and the Dynamo described in
  231. 10:01Plants both are not interesting they
  232. 10:03just return some details first one
  233. 10:05details about the user or role that is
  234. 10:07being used and the second one is just
  235. 10:09the returns details about the endpoints
  236. 10:12of the current AWS region so
  237. 10:15uh so yeah unfortunately I don't have
  238. 10:18any screenshot for other sensitive
  239. 10:19permissions but in the past I've seen
  240. 10:21credentials with access to history
  241. 10:23history bucket lumped up functions even
  242. 10:25an access to dinner mode DB tables in
  243. 10:28ETC there are so many things that might
  244. 10:31go wrong
  245. 10:33all right so there is a chance that the
  246. 10:37honor quanticated role is explicitly
  247. 10:39disabled in the console so in that case
  248. 10:42when you attempt to generate an identity
  249. 10:44ID like in the previous step it will
  250. 10:47actually throw the following error and
  251. 10:49authenticated access is not supported
  252. 10:51for this identity poll but later in the
  253. 10:54talk I'll show you another
  254. 10:55misconfiguration that you may actually
  255. 10:57leverage to to obtain and to get an
  256. 11:00account on an application that does not
  257. 11:02provide any user signup or registration
  258. 11:04so just be patient
  259. 11:07all right so in in that case assuming
  260. 11:11that you do have an access to that
  261. 11:13authenticated account once you log into
  262. 11:15your account just keep an eye out for
  263. 11:18this API call that is exchanging the ID
  264. 11:20token as you can see in this screenshot
  265. 11:22and it is exchanging the ID token into
  266. 11:24temporary AWS credentials similarly you
  267. 11:27can just use the tools that I've shown
  268. 11:28you to fetch the permissions associated
  269. 11:30with these credentials and see if there
  270. 11:32are loads any further access to their
  271. 11:34AWS services
  272. 11:36all right let's get to the second
  273. 11:38misconfiguration
  274. 11:40uh the second one is when the
  275. 11:42application does not allow sign up or
  276. 11:44any self registration let's say you have
  277. 11:46a SAS app or an admin portal for which
  278. 11:49the user provision is only done by an
  279. 11:52administrator
  280. 11:53they might not have it implemented any
  281. 11:56public signup for example from but they
  282. 11:59have lift this sign up API action
  283. 12:01enabled in the deep in the AWS console
  284. 12:04which is misconfiguration
  285. 12:07uh so from my personal experience signup
  286. 12:11is always enabled by default uh when
  287. 12:13creating a user pool in the console so
  288. 12:16as unless you explicitly disable it an
  289. 12:20attacker will can Leverage The cognitive
  290. 12:22API endpoint in order to sign up and
  291. 12:25provision an account for themselves
  292. 12:28how we can do that so to do that to test
  293. 12:32against this particular misconfiguration
  294. 12:34you will need the application client ID
  295. 12:37which is usually hard-coded in the
  296. 12:39source code AS we've seen before and
  297. 12:42also you need the client ID which is
  298. 12:44usually sent over to Cognito API when
  299. 12:47you try to log in to your account so
  300. 12:49it's easier to find just use burpswich
  301. 12:51then you will simply next send an API
  302. 12:54call to sign up with your email address
  303. 12:57using the AWS client of course if the
  304. 13:00sign up is lift enabled misconfigured
  305. 13:02then you should receive E6 DJ code to
  306. 13:05your email address that you used for
  307. 13:06sign up
  308. 13:08so but as you can see here uh in the
  309. 13:12screenshot here the this is a field sign
  310. 13:14up below but in the middle you can see a
  311. 13:16successful sign up that says that we we
  312. 13:19should receive a code or email
  313. 13:22so
  314. 13:24oh by the way uh if you don't want to
  315. 13:27use AWS client you can always send just
  316. 13:30direct HTTP call to Cognito API endpoint
  317. 13:33as follow as you can see here in the
  318. 13:34screenshot so this is just a replacement
  319. 13:36if you don't want to use AWS client you
  320. 13:39can construct this HTTP request make
  321. 13:42sure you're using the upper create HTTP
  322. 13:44header for sign up here as you can see
  323. 13:46and the body is properly formatted in
  324. 13:49Json so this is exactly the same as
  325. 13:52using AWS client I prefer the AWS client
  326. 13:54to be honest it's pretty easy
  327. 13:57all right so if the email verification
  328. 13:59is also enabled
  329. 14:01you will you won't be able to access
  330. 14:04your the account unless you confirm it
  331. 14:06but that is quite easy so you can again
  332. 14:09leverage AWS client Again by simply
  333. 14:12providing the email address the client
  334. 14:14ID the region and the six digits that
  335. 14:17you received in the email once you hit
  336. 14:19enter it will confirm your account so
  337. 14:23it's pretty easy to confirm it that's
  338. 14:25not a problem sometimes you might be
  339. 14:26able to sign up you get an account but
  340. 14:29it doesn't have any roles any role
  341. 14:32assigned to it unfortunately that could
  342. 14:34happen
  343. 14:35but there is a chance that uh
  344. 14:40well so oh sorry
  345. 14:44this is the so basically if you want to
  346. 14:47confirm your account you can all also
  347. 14:48use the HTTP request here so what I was
  348. 14:52saying earlier is that there is a chance
  349. 14:53that sometimes when you sign up the user
  350. 14:55doesn't have any group assigned so you
  351. 14:58will not get any access to the
  352. 14:59application features or functionalities
  353. 15:01but this is but in this particular case
  354. 15:04you can still use the generated
  355. 15:05credentials and test them against
  356. 15:07liberal permissions as we've seen in the
  357. 15:10first misconfiguration
  358. 15:12all right a third misconfiguration
  359. 15:14another prominent one is that you can
  360. 15:17come across uh writable sensitive user
  361. 15:20attributes
  362. 15:22so basically when you create a user pool
  363. 15:24in the console it allows you to set up a
  364. 15:26number of standard user attributes such
  365. 15:28as email full name birthday phone number
  366. 15:31Etc these are supported by default and
  367. 15:34these attributes are usually writable
  368. 15:37which means that the user can update
  369. 15:39them at any given time however the
  370. 15:42developer has the ability to create
  371. 15:45custom user attributes
  372. 15:48as you can see here you can create
  373. 15:49custom attributes uh like the user role
  374. 15:53it's a custom attribute that I'm
  375. 15:55creating here in screenshot to store the
  376. 15:57role and level of access of the user
  377. 16:00which they're supposed to have but what
  378. 16:02can go wrong here a lot actually
  379. 16:05so the security issue is that developers
  380. 16:07often forget to set sensitive user
  381. 16:10attributes as readable only
  382. 16:12so they leave them they they leave them
  383. 16:16as writable which means that even if the
  384. 16:18application he does not allow the user
  385. 16:21to change its value they can always
  386. 16:23Leverage The cognitive API to update it
  387. 16:26as we've seen in earlier examples
  388. 16:28so a lot can go wrong since the user can
  389. 16:31update their role for example to an
  390. 16:33admin or change their membership status
  391. 16:35or Etc depends
  392. 16:38all right so how we can do that how we
  393. 16:40can update uh the user attribute so the
  394. 16:43first step is to fetch the current
  395. 16:45user's attribute and see if there are
  396. 16:47any custom ones that they are not
  397. 16:49supposed to update
  398. 16:50uh so once you're logged into your
  399. 16:52account you will obtain an access token
  400. 16:55as you can see here in the authorization
  401. 16:56header then you can just copy it and
  402. 16:59simply execute the ews command to get
  403. 17:02the user attributes it will look
  404. 17:04something like this in the screenshot so
  405. 17:06you can see all the user attributes that
  406. 17:08are supported your own you can see that
  407. 17:10your own information there so upper
  408. 17:13apart from the standard ones always look
  409. 17:15for the attributes that start with the
  410. 17:18word custom
  411. 17:20okay
  412. 17:21so you can directly all you can also
  413. 17:24directly call the coordinator API if you
  414. 17:26don't want to use the AWS client to fix
  415. 17:28the user attributes so you would you
  416. 17:30want to look out for attributes that
  417. 17:32start with custom as I mentioned example
  418. 17:35of custom error reviews that I've come
  419. 17:36across personally are like is admit
  420. 17:39custom is admin uh user role is active
  421. 17:43is approved access level and these are
  422. 17:45all sensitive as they control the user
  423. 17:48level of access most of the time
  424. 17:51and naturally the next step is to try to
  425. 17:55update these attributes and see if they
  426. 17:58are only readable or also lived as
  427. 18:01writable which is bad so you so uh you
  428. 18:05can use the AWS commands as as posted
  429. 18:09there or you can just use the HTTP
  430. 18:11request to update it so if one like if
  431. 18:15it succeeded see if it succeeds you will
  432. 18:17get a 200 okay status
  433. 18:21here we've been we try to update the
  434. 18:24user role from a standard one to an
  435. 18:27admin so change the value to admin and
  436. 18:31like yeah funny enough funny story just
  437. 18:34when my talk was actually announced I
  438. 18:36had someone from the Bad Bunny Community
  439. 18:37Reach Out and share the critical bug
  440. 18:40that they found just exactly by updating
  441. 18:43the their user role to Super admin and
  442. 18:46so basically they found in the JS file
  443. 18:49that there is a role called super
  444. 18:50adamant right and they just like hit the
  445. 18:54API Cognito as you can see in the
  446. 18:57message here uh to update their their
  447. 19:00role to a super admin and luckily enough
  448. 19:03they just became the admin of the
  449. 19:05platform so this is pretty common in my
  450. 19:07boundaries and even when you're doing
  451. 19:08penetration testing as well it's pretty
  452. 19:10common
  453. 19:11the last one the fourth misconfiguration
  454. 19:14uh I've that I've come across is when
  455. 19:16the application these are lows I mean
  456. 19:18doesn't allow updating the email address
  457. 19:21as you can see here in the screenshot
  458. 19:23but I mean there are both clients and
  459. 19:25even server-side checks but it is always
  460. 19:28again possible to change it through the
  461. 19:30API cognito
  462. 19:32so you just need to get your own access
  463. 19:34token when you're logged into your
  464. 19:36account and then execute the ews command
  465. 19:39to set a new email address so you can
  466. 19:42always change it using the API Cognito
  467. 19:44API
  468. 19:46so there are some applications that do
  469. 19:48not really require email verification
  470. 19:50because they do not expect the user to
  471. 19:53be able to change it in the first place
  472. 19:55so this can be done from the AWS console
  473. 19:57as you can see uh and for apps that rely
  474. 20:01on email domain for granting the user
  475. 20:03special permissions or access this will
  476. 20:06definitely be passed the check controls
  477. 20:08and result in that privilege escalation
  478. 20:11is pretty easy
  479. 20:13so even when email verification is
  480. 20:15indeed required uh like a lot of
  481. 20:18applications do actually require
  482. 20:19verification there is another problem
  483. 20:22that arises is that the email attribute
  484. 20:25value as you can see here is already
  485. 20:27changed and said to the new unverified
  486. 20:30email address so although the email
  487. 20:32verified attribute does say that the
  488. 20:35email is not confirmed here it is false
  489. 20:38but
  490. 20:40the best security practice is just to
  491. 20:42never update the email until the user
  492. 20:44verifies it
  493. 20:47so what I've noticed uh with Cognito is
  494. 20:50that the user would successfully still
  495. 20:52be able to log in with the unverified
  496. 20:54email address so if that the application
  497. 20:57is not checking the email verified
  498. 20:59attribute this will definitely result in
  499. 21:02privileged installation it's pretty easy
  500. 21:04so you should always check the email
  501. 21:07verified if it's set to true or false
  502. 21:10uh for this particular reason ews they
  503. 21:13recently introduced a new security
  504. 21:15configuration which is unfortunately now
  505. 21:18enabled by default and understanding
  506. 21:20it's usually still confusing to most
  507. 21:22people so basically uh if you enable
  508. 21:25this security feature uh the email
  509. 21:27attribute will not be updated until the
  510. 21:30user has verified it which is the way to
  511. 21:32go but most applications still have it
  512. 21:35disabled especially because it's new the
  513. 21:37configuration is new and just still not
  514. 21:39enabled by default from my experience
  515. 21:41from what I've seen
  516. 21:43so we'll take uh this report on hacker
  517. 21:47one it's public report as a quick case
  518. 21:49study just to illustrate this
  519. 21:51misconfigurations uh that I just
  520. 21:54mentioned so the researcher here was
  521. 21:57able to achieve uh E4 account takeover
  522. 21:59on Flickr which is uh I think it's a
  523. 22:02Yahoo acquisition
  524. 22:04so just by abusing Cognito and they paid
  525. 22:06him 7.5 K just for it being a critical
  526. 22:09bug
  527. 22:11so I tried to summarize everything in
  528. 22:13this slide here so basically we have our
  529. 22:17victim user with the email Jack at
  530. 22:19domain.com
  531. 22:21so Flickr app was not allowing email
  532. 22:23update it was not a loan user to change
  533. 22:25their email but the researcher as I met
  534. 22:28I told you before he managed to change
  535. 22:29it just using the cognitive API it
  536. 22:32doesn't matter if there is like a client
  537. 22:33or server side Chase as long as he you
  538. 22:36can always use the cognitive Epi as
  539. 22:38demonstrated earlier so they updated
  540. 22:40their email to Jack at dominion.com but
  541. 22:44notice that Jack with a capital J which
  542. 22:47is the same email as our victim but with
  543. 22:49a capital J remember that so here there
  544. 22:52are two misconfigurations first one is
  545. 22:54that the email address attribute was
  546. 22:56lift writable it was lift with the
  547. 22:58writable permission in the console so it
  548. 23:00did not matter if it was disabled in the
  549. 23:02app since you can always update it from
  550. 23:04the Cognito API and the email second one
  551. 23:08is the email was Lyft case sensitive
  552. 23:10which they could have changed to
  553. 23:11insensitive in the console so that one
  554. 23:13was that were those were two
  555. 23:15misconfigurations
  556. 23:16then the researcher managed to
  557. 23:19successfully log in with the unverified
  558. 23:22email they have not verified the email
  559. 23:24but they still managed to log in with it
  560. 23:27so two issues arise one is the email
  561. 23:29verified attribute was not checked if it
  562. 23:32was set to true and the second one is
  563. 23:35the previous security configuration was
  564. 23:37not enabled either so otherwise if they
  565. 23:40enabled the previous security
  566. 23:41configuration they mentioned the email
  567. 23:43value wouldn't have been updated until
  568. 23:46you the user verified it so the last
  569. 23:49piece of the puzzle was the fact that uh
  570. 23:52there was an email normalization
  571. 23:53happening uh at the application Level so
  572. 23:57the capital J was changed to smaller J
  573. 23:59so the email matched the victim's email
  574. 24:02and the attacker was just able to log
  575. 24:04into the victim's account easily as you
  576. 24:07can see it is pretty easy to mess up
  577. 24:09things when you're configuring Cognito
  578. 24:10so it's very important to be very
  579. 24:13careful
  580. 24:15so here I have some recommendations for
  581. 24:16developers uh this one I've seen so far
  582. 24:20these are some recommendations always
  583. 24:22remove sensitive details from server
  584. 24:24responses any unnecessary details just
  585. 24:27remove it if you're not using sign up if
  586. 24:30it's not needed disabled in the console
  587. 24:32as well make sure you disable
  588. 24:34unauthenticated roles if they are not
  589. 24:36required uh always review the
  590. 24:39permissions that are associated with the
  591. 24:42authenticated and unauthenticated role
  592. 24:44and always always ensure the least
  593. 24:47privileged access that like always Grant
  594. 24:50the user minimum privilege access
  595. 24:52and then evaluate will evaluate all the
  596. 24:55user attributes and if they do not need
  597. 24:58to be updated disable the writing
  598. 25:00permission if not necessary and remember
  599. 25:02that the email clean I mean the email
  600. 25:05attribute can always hold an unverified
  601. 25:08email address as we have seen in the
  602. 25:10report that we just mentioned
  603. 25:14that's it thank you so much for tuning
  604. 25:15in appreciate it reach out on Twitter if
  605. 25:18you have any questions or anything or
  606. 25:20just check out my website and you can
  607. 25:22always contact me from there as well
  608. 25:24thank you so much

About this transcript

This page contains the full transcript of #NahamCon2022EU: Hunting for Amazon Cognito Security Misconfigurations by@yassineaboukir by NahamSec, generated from the public captions YouTube serves with the video. The transcript has 3,991 words across 608 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.