云泥殊路 云上环境数据泄露的探讨——姚威

QCon大会

2019/05/14 发布于 技术 分类

QCon  QCon2019 

文字内容
1. b y I D p 0 t t 1
3. ID: p0tt1 ( LCS ) Wi-Fi CEO [!]“ [!]“ ” Wi-Fi LCS / Wi-Fi Wi-Fi ”
4. 01 02 03 04
6. X 70 X
8. 40 200 51 ecarx • “Internal” • Internal • Internal code.***yun.com Internal 51
9. “ 01. AK access key 02. CodeSpaces AccessKey AccessKeyId AccessKey CodeSpaces AccessKeyId AccessKeySecret AccessKeySecret AccessKey Github root ”
10. Amazon S3 Patient Home Monitoring 47GB 315,363 PDF Amazon S3 Data Trust RNC AWS S3 1.1 TB 15 Deep Root Analytics TargetPoint 1.98 GoDaddy GoDaddy S3 bucket GoDaddy AWS CPU 31000
11. GitHub Gitee Blog
14. 01. • CSA STAR • • • ISO 27001 02. • • • • DDoS /Web / / / /
16. Ø Ø 1 2
17. AccessKey GitHub accessKeySecret AccessKey Github & • Github Gitee • AccessKey • • AK AK API • OSS • •
18. ECS Ø ECS Ø AK api “ root ”
19. AWS AccessKey GitHub aws_access_key_id aws_access_key Github AWS S3 AK • • bucket • • S3 bucket Javascript Javascrip
20. hadoop hadoop
22. Mongodb Elasticsearch
24. • • • • ;
25. AK API API