TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Researchers Uncover 'Massive Security Flaws' In Amazon Cloud

25 点作者 d0ne超过 13 年前

3 条评论

TimothyFitz超过 13 年前
The researchers uncovered an XML Signature Wrapping attack, which requires the attacker has access to the plaintext of a correctly authorized XML request sent to Amazon. Given that every client I know of uses https for EC2 APIS, this isn't what I would call a "Massive Security Flaw".<p>More details on XML Signature Wrapping here: <a href="http://clawslab.nds.rub.de/wiki/index.php/XML_Signature_Wrapping_-_Simple_Context" rel="nofollow">http://clawslab.nds.rub.de/wiki/index.php/XML_Signature_Wrap...</a>
评论 #3203626 未加载
maratd超过 13 年前
Why is this a story if the flaws have already been fixed? I have no expectations of perfection from Amazon, just responsiveness.
评论 #3204955 未加载
DiabloD3超过 13 年前
For those looking to ditch Amazon over their mismanagement, try a real VPS provider like RapidXen.