iTnews Asia
  • Home
  • News
  • Cloud

AWS had a dangerous undocumented API

AWS had a dangerous undocumented API

Undetectable reconnaissance.

By Richard Chirgwin on Jan 18, 2023 11:08AM

An undocumented API in AWS' management console could have allowed attackers an undetectable surveillance channel, a security researcher has said.

AWS quietly fixed the issue in October 2022 after being alerted by Datadog in March 2022.

The Datadog researchers who discovered the API realised it could bypass AWS CloudTrail logging. 

The API, documented here, would mean specific identity and access management (IAM) requests would not be logged.

“This technique would allow an adversary to perform reconnaissance activities in the IAM service after gaining a foothold in an AWS account—without leaving any trace of their actions in CloudTrail”, Datadog’s senior security researcher Nick Frichette wrote.

Datadog discovered the API, called “iamadmin”, by watching connection requests in the browser developers’ tools while browsing the AWS Management Console.

From there, the researchers discovered 13 methods they could invoke with iamadmin, allowing them to list group policies and user counts, list users, and more.

“Being able to bypass CloudTrail logging and getting the results of those calls has serious implications for defenders because it limits their ability to track what an adversary has done in an environment and what actions they’ve taken”, Frichette’s post states.

“Furthermore, this technique also makes it possible to bypass GuardDuty for findings such as IAMUser/AnomalousBehavior, because GuardDuty uses CloudTrail as a data source, and it can’t alert on something it can’t see.”

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
api aws cloud datadog security vulnerability

Related Articles

  • A data-first AI strategy is critical to managing security threats in 2026
  • Malicious AI inputs are creating a new and critical security threat
  • How the public sector can ensure their cloud sovereignty
  • Beware the pitfalls of using a ‘DIY security’ approach
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

AIA to hit 90 percent cloud adoption by end of 2022

AIA to hit 90 percent cloud adoption by end of 2022

Singapore’s HTX deploys air-gapped cloud to enhance AI safety for public

Singapore’s HTX deploys air-gapped cloud to enhance AI safety for public

How nations can forge their digital futures with Sovereign AI

How nations can forge their digital futures with Sovereign AI

Traveloka scales its recommendations with Amazon Personalize

Traveloka scales its recommendations with Amazon Personalize

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.