build1 publisher
A WAF role with account-wide S3 access turned one SSRF into 106 million records
Trust Boundary's walkthrough of the 2019 Capital One breach puts the weight on the IAM role attached to the firewall instance, and says the OCC consent order that followed does not mention server-side request forgery at all.
Publishers:dev.to
Reality
- Evidence62
- Adoption55
- Hype gap+10
- Incentives35
- Confidence66