You’ve heard about cloud, big data, server-less infrastructure, web scale, and other buzzwords that cause VCs to throw money at people - but how does this help you? If you’re getting bored going over the same checklist in your pentests then you’re missing out on what some of these new technologies can offer you. Using some of the newer cloud technologies not only can you automate all of your workflows, but you can do so with almost zero maintenance at a low cost with almost infinite scalability! This talk will show you how to blow conventional pentesters out of the water using some cool new technologies along with a little bit of trickery.
Some of the topics we’ll go over include: * Cheap and scalable rainbow tables with BigQuery, 5TB in 10 seconds * SQS & Lambda, like Burp Intruder but 10K QPS * Scalable GPU Clusters on the cheap with Spot Instances and Elastic Beanstalk * Cloud exit nodes, rotating IPs via Elastic Beanstalk and nano instances * Cost effective fuzzing with Elastic Beanstalk and Spot Instances
(This was originally presented on November 16, 2018 at Kiwicon 2038).
5. Hola!
I am Mandatory
About
Security engineer, XSS Hunter, DNS, and more!
Industry Certifications
High School Diploma
Blog Twitter
TheHackerBlog.com @iammandatory
9. EHLO
I am Moloch
About
I like computers.
Industry Certifications
High School Diploma
Occupation Twitter
Senior Associate, Bishop Fox @littlejoetables
67. What is Big Query?
BigQuery is Google's serverless,
highly scalable, enterprise data
warehouse designed to make all
your data analysts productive at an
unmatched price-performance.
68. What is Big Query?
It’s a big database you can crap
terabytes of JSON into and query it.
91. Traditional GPU Clusters
• High upfront costs ( $2-3k+ )
• Server maintenance
• User & resource management
• Hardware failures are expensive
• Power consumption
93. AWS Services
• Spot Instances
• Elastic Beanstalk
• Lambda Functions
• API Gateway
• Simple Queue Service ( SQS )
• Simple Storage Service ( S3 )
94. AWS Services
• Spot Instances
• Elastic Beanstalk
• Lambda Functions
• API Gateway
• Simple Queue Service ( SQS )
• Simple Storage Service ( S3 )
95. AWS Spot Instances
• It’s EC2 but at up to 90% off the
regular pricing
• You set a bid price, if the current
price is below yours then
instances are started, if they’re
above then they are killed ( 2
minute warning )