A Purple Team View of Serverless and GraphQL Applications

By Abhay Bhargav on 13 Sep 2019 @ Globalappsec
🔗 Link
We need help to complete this entry! Missing: presentation, Video
I can help!
#purpleteam #cloud-workload-protection #serverless #lateral-movement #security-testing #application-pentesting
Focus Areas: 🛡️ Security Operations & Defense , 🔐 Application Security , ☁️ Cloud Security , ⚙️ DevSecOps , 🎯 Penetration Testing

Abstract

The presentation will begin with quick refresher on Serverless functions and GraphQL Applications. The author will deploy a serverless function with GraphQL to demonstrate.

The presentation with demo will also highlight some common attacks against serverless functions, namely:

Subsequently, author will demonstrate attacks against GraphQL Functions like:

Finally the presentation ends with the author demonstrating attacks against Serverless-GraphQL Applications, where the author will use Remote Code Execution and DoS Style queries to demonstrate specific attacks leading to cloud API-based lateral movement and DoS leading to financial exhaustion

All the while, the author will highlight some key deficiencies in the lack of tooling, “batteries-included” security frameworks and DIY validation that might exacerbate these flaws