engaged in professional services for web applications and public clouds. He is involved in activities to raise awareness of security in public cloud and web applications through activities in external organizations such as ISOG-J WG1, and speaking at and holding workshops at JSAC (2024), AWS DevDay (2023), and Security-JAWS DAYS (2023). Norihide Saito / azara (X @a_zara_n) Flatt Security Inc.
Inc. After graduating from the Graduate School of Kagoshima University, Eiji joined Flatt Security in April 2021. As a security engineer, he is mainly in charge of web application and smartphone application assessments. He has been involved in security camp-related events in the past, so he has a wide range of interests, from hardware to software. His hobbies are vulnerability research and weight training.
vulnerabilities using just a tool0 Vulnerabilities that can be detected using a tooA Inadequate S3 setting ..C EDo XSS due to metadata modificatio( ... Vulnerabilities that cannot be detected using a tooA
and causes excessive consumption of cloud resources, resulting in high usage fee1 0 An attack on the total amount of data stored in a mont 0 An attack on the number of requests in a mont 0 An attack on the amount of data transferred in a month
allowed to access the Principa@ H Do not set “AWS: *” inappropriately within the Principa@ H Set according to the “principle of least privilege” for Actions and Resource1 H If “Effect: Allow” is selected, do not set “Action: *” or “Resource: *” inappropriatelyB H Narrow down the scope of the S3 bucket that is allowed to access the ResourcF H Do not set “*” inappropriately in the ResourcF H Introduce a tool that can perform automatic detection
and causes excessive consumption of cloud resources, resulting in high usage fee1 0 An attack on the total amount of data stored in a mont 0 An attack on the number of requests in a mont 0 An attack on the amount of data transferred in a month
and causes excessive consumption of cloud resources, resulting in high usage fee1 An attack on the number of requests in a mont An attack on the amount of data transferred in a month 0 An attack on the total amount of data stored in a mont 0 0
more 0.023 USD / GB 450 TB / month 0.024 USD / GB 50 TB / month 0.025 USD / GB Storage data capacity Price The price varies depending on the amount of data stored on S The more data you store, the lower the price per GB
a month Increase the total amount of data stored per month An attack on the total amount of data stored in a month Uploading a 500TB file 11500 USD / month huge
and causes excessive consumption of cloud resources, resulting in high usage feeH F An attack on the total amount of data stored in a mont F F An attack on the amount of data transferred in a month An attack on the number of requests in a mont
if the number of requests increase( 8 The price differs depending on the metho1 8 In the case of GET, the price of the transferred data is also added GET, SELECT, and all other requests (per 1000 requests) 0.00037 USD PUT, COPY, POST, LIST requests (per 1000 requests) 0.0047 USD Billing Item Price
Increase in the amount charged per request due to high volume access An attack on the number of requests in a month 10 million requests sent 47 USD / month The damage was minor.
and causes excessive consumption of cloud resources, resulting in high usage feeP H An attack on the total amount of data stored in a mont H An attack on the number of requests in a mont H An attack on the amount of data transferred in a month
transferred from S3 will affect the price3 A The more data you transfer, the lower the price per GB will be. 150 TB / month or more 0.084 USD / GB 100 TB / month 0.086 USD / GB 40 TB / month 0.089 USD / GB 10 TB / month 0.114 USD / GB Amount of data transferred Price
month Increase in the amount charged due to the amount of cumulative data transferred An attack on the amount of data transferred in a month Downloading a 150TB file 12600 USD / month huge
exact matcD P partial matches are not use' P startWitD P endsWitD P inclue5 P When using regular expressions, be careful of unintended matches with stringsU P /^image/(png|jpeg|jpg|gif)$/
vulnerabilities detectable by tools: Shisho Cloud A The only domestic SaaS that A Has a very competitive pricing model, with monthly fees going as low as can assess web applications and the cloud in their entirete 20,000 - 30,000 yen.
manual assessments: Security Assessments Security Assessments & Penetration Testing R In addition to the usual “black box” testing, we also perform “white box” testing, i.e. G R In addition to the increase in the volume of vulnerability reports, we can also provide more specific instructions on how to fix them. source code analysis
Shisho Cloud and manual security assessments Furthermore, the two projects mutually reinforce each other. Security Assessments & Penetration Testing Provides advanced automation Allows you to focus on the parts that “only a person can do” The engineer's knowledge is returned as a detection rule. We continue to strengthen automation.
triag) 0 vulnerability assessment according to the context of the application Security Assessments & Penetration Testing Provides advanced automation Allows you to focus on the parts that “only a person can do” New knowledge gets added in as new detection rules. We continue to strengthen automation.