Same Thing We Do Every Few Minutes, Pinky - Try to Take Over All Your Subdomains!

Same Thing We Do Every Few Minutes, Pinky - Try to Take Over All Your Subdomains!

RSA Conference via YouTube Direct link

We can no longer afford manual processes

8 of 24

8 of 24

We can no longer afford manual processes

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

Same Thing We Do Every Few Minutes, Pinky - Try to Take Over All Your Subdomains!

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Intro
  2. 2 Sidebar - an intro to DNS
  3. 3 What is subdomain takeover?
  4. 4 Why can't cloud providers simply make it not a thing?
  5. 5 How did a takeover happen during training?
  6. 6 Talking to the developers
  7. 7 Disclosure leads to heightened interest, confusion
  8. 8 We can no longer afford manual processes
  9. 9 How do we get better? Faster?
  10. 10 What tools are in the space?
  11. 11 So we built submon-cli
  12. 12 Choices made
  13. 13 The architecture of submon-cli
  14. 14 Not a simple match of DNS resource name
  15. 15 How does this fail?
  16. 16 There are other kinds of SDTO...
  17. 17 Oracle - tenancy namespace in DNS names
  18. 18 AWS-randomly assigned name servers
  19. 19 Azure - machine readable list of IP ranges
  20. 20 Postpone DNS name release in Enterprise subscriptions
  21. 21 Event notification (fast!) on DNS name release
  22. 22 Mapping between DNS names, resource types
  23. 23 And finally...
  24. 24 Questions?

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.