Apple and AWS: Security?
October 13, 2020
DarkCyber noted an essay-style report called “We Hacked Apple for 3 Months: Here’s What We Found.” The write up contains some interesting information. One particular item caught our attention:
AWS Secret Keys via PhantomJS iTune Banners and Book Title XSS
The information the data explorers located potential vulnerabilities to allow such alleged actions as:
- Obtain what are essentially keys to various internal and external employee applications
- Disclose various secrets (database credentials, OAuth secrets, private keys) from the various design.apple.com applications
- Likely compromise the various internal applications via the publicly exposed GSF portal
- Execute arbitrary Vertica SQL queries and extract database information
Other issues are touched upon in the write up.
Net net: The emperor has some clothes; they are just filled with holes and poorly done stitching if the write up is correct.
Stephen E Arnold, October 13, 2020