View all newsletters
Receive our newsletter - data, insights and analysis delivered to you
  1. Technology
  2. Cloud
May 1, 2015

Infrastructure clouds left at risk from talentless hackers

Microsoft Azure and friends may not be being secured properly.

By Jimmy Nicholls

Symantec has warned that infrastructure-as-a-service (IaaS) clouds such as Microsoft Azure are vulnerable to attacks even from unskilled hackers.

A recent investigation by the security vendor showed that unsecured cloud "buckets" used for storing data could be accessed without the need for login details so long as the hacker could guess the right web address.

This was done by writing a script capable of guessing the domain names, even though there was no central listing of all the domain prefixes for the given cloud provider.

Candid Wueest, threat research at Symantec, said in their research that: "Not all of the accessible data blobs contained sensitive information. Some files were just images or public html files."

However he added that one particular file was uncovered from a payment processor company which turned out to be a database backup that included credit card logs, user IDs, email addresses and passwords.

Such data could then be sold on cybercrime forums for use by fraudsters and other hackers.

"Our research has proven that this attack method is highly feasible and the sensitive data that was uncovered is real, indicating that this is not just a hypothetical attack scenario," Wueest said.

Content from our partners
Powering AI’s potential: turning promise into reality
Unlocking growth through hybrid cloud: 5 key takeaways
How businesses can safeguard themselves on the cyber frontline

"The problems illustrated in this research are not isolated to just one single cloud service provider. Similar attacks could be carried out against other cloud infrastructures."

Cloud customers are advised to take the time to understand their product settings in order to avoid falling prey to similar cyberattacks, as well as keep an event log to monitor who is accessing the service.

Websites in our network
Select and enter your corporate email address Tech Monitor's research, insight and analysis examines the frontiers of digital transformation to help tech leaders navigate the future. Our Changelog newsletter delivers our best work to your inbox every week.
  • CIO
  • CTO
  • CISO
  • CSO
  • CFO
  • CDO
  • CEO
  • Architect Founder
  • MD
  • Director
  • Manager
  • Other
Visit our privacy policy for more information about our services, how Progressive Media Investments may use, process and share your personal data, including information on your rights in respect of your personal data and how you can unsubscribe from future marketing communications. Our services are intended for corporate subscribers and you warrant that the email address submitted is your corporate email address.
THANK YOU