The Capital One breach was not an SSRF story
Originally published at trustboundarystudio.com . The video version, with diagrams, is on YouTube . Key facts When: 22 to 23 March 2019. Discovered 17 July 2019, after an outside party emailed Capital One's responsible disclosure address. Scale: Personal data of 106 million people. Entry: Server-side request forgery through a misconfigured web application firewall, returning IMDSv1 credentials.…
On March 22-23, 2019, personal data of 106 million individuals was stolen from Capital One. The breach was discovered 17 July 2019, after an outside party emailed Capital One's responsible disclosure address. Instead of being a server-side request forgery (SSRF) story, the breach was caused by a misconfigured web application firewall (WAF) that allowed server-side request forgery.
The WAF had an IAM role attached, which gave it permissions to access other AWS services. The firewall instance could read S3 buckets across the account, including those containing credit card applications dating back to 2005. The breach resulted in an $80 million civil money penalty from the Office of the Comptroller of the Currency (OCC) and a $190 million class action settlement.
The OCC's consent order found that Capital One failed to establish effective risk assessment processes and identify control gaps before migrating its IT operations to the cloud.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.