Platform-as-a-Service Cloud Security Scrutinized by Trustwave

Transcription

and that was on cloud-based um security yeah problems with um we identified with certain nuances with platform as a service yeah where end users or developers can go in and take down code or take code from community repositories yeah and no one really trust no one really extends that code when you mean platform as a service are we talking the standard openshift the cloud foundry that kind of actually openshift was an example we used yeah so openshift is vulnerable today um so not necessarily vulnerable yeah there's not a vulnerability in openshift okay but the way that the way that services are sold and the way the services are marketed as you have to worry about security right um we identified that um if you go and you um go to the openshift github repository and you say well i'm going to install wordpress yeah you go to the repository they have quick starts sure sure allow you to download yeah download wordpress well that the versions of wordpress and the version of joomla the version of ruby on rails yeah is all updated versions really which have a handful of cds associated with them there was one instance and then we also found that no one really polices this no one really polices the um basically who audits this code so we basically put together a scenario where um myself and my co-presenter steve osepe i played the boss and told him we need to get a chat server up by three o'clock today and so he basically went live on stage went to github found a tech support application yeah basically logged into his account on openshift yeah downloaded the code um basically installed it got it running in the cloud and then we have people actually logging in in the audience yeah utilizing it um but it was actually code that we planted in um in github that had a fake vulnerability in it that we were able to basically hit a button and it does like a web shell so we wanted to show that if that action really was to happen where the person's under pressure you have to get this up and running really really quick and they go and they just grab this cartridge or this this cloud community application yeah they don't look at the code they just go install it now it's introduction two hours later now with openshift because i know there's got to be crystal clear there's three variants right there's openshift origin openshift enterprise and then openshift online so this was just openshift online yeah the free version it was the free version yeah so we're we're testing that out you could you could upgrade it and yeah you can have from start to finish it took less than 10 minutes of getting running and basically he didn't have to code he just copy and pasted the instructions yeah yeah they were in all they're in github so we want to show they know this is where they're being marketed this is what's being marketed towards individuals who maybe not may not even have the ability to review code or be able to see if there's a problem they just go in they cut and paste and they go up and go it's like almost like you're downloading the app on your iphone yeah sure i need this application up and running i need to create a blog so you go and you download the code you install it and you're up and running then you tweak it and configure it yeah but you don't know what it's doing you don't know if there's vulnerabilities you don't know if there's so with the red hat guys because i know them reasonably well in the spirit of full disclosure um i also know that they do a lot of back patching whether it's kernel or whatever uh should there be some kind of scanning in there and did you verify that there wasn't well i guess in your case you just uploaded code there's no question there's no opportunity for them to backport anything no no so we were focusing at the um really at the application yeah we were basically taking the assumption that like i know anybody else with that red hat's doing the right thing on the at the os level the rest of the stack is being taken care of we're focusing on this is what we have control over as using a platform as a service this is what we can touch this is what we can do and these are the bad things that can happen when we're not we're not we're not doing we're just going through that these kind of services recommend now would the same experience have been the equivalent if i was using state staccato cloud foundry or one of the other uh public uh past services today yeah possibly yeah i mean we just we just basically we weren't picking on you know open shift and yeah it was basically this was a free easy sure easy um took five minutes to get an account 10 minutes to get up and running and we did this horrible thing to our business yeah that's exciting and then from a disclosure perspective because you are a respectable company of course yeah um did you disclose any of this back up to uh red hat and the other communities that you may have touched to say this is an issue you should do it or is this just a a process thing and it's not you know a cve level it's not a cve right so it's a process thing it definitely is a process thing i mean it's more of awareness and it's something really they can't control right i mean they have no control over this because anybody like we did anybody can go and write your own software they can run on their platform like i can go and download the latest version of joomla back door sure package it put make a cartridge of it throw it up in github and say this is openshift joomla yeah and they have no control over it this is out of their control this is almost this is similar to a problem like certainly like google android has with third party stores sure they can't control what's going on in the third-party stores at all and so people are planning mail we're there and then end users are saying i want to download it from this other store right now google has no control over that sure so the solution then some kind of lockdown verified store or some kind of keys for each developer so that things can be revoked if there's a challenge i mean i think an official store where there's there's a subset of packages so the popular stuff you know like ruby on rails and wordpress those that are you know the subset that is um that has been verified by some organization yeah maybe it's cloud providers and some cloud providers do have official packages i mean that's pretty popular hosting providers you log into your control panel right and you say i want to turn on wordpress yeah you turn that on that came from that hosting provider sure presumably it's been maintained presumably it's not five years old um i ventured i guess there's some question providers that have five-year-old versions of wordpress running still but for the most part there's one single source you're getting from it's not this community sure where people can upload it and have all good intentions to maintain it yeah but they go off and do something else and they leave this they abandoned sure ninja target devil's advocate you know i assume pass like standard amazon almost or even just old style web server it's just plain vanilla it's just that medium on which i can install whatever i want is that not the right way that i should be thinking of past then because there's additional expectations as a user yeah i mean for for for i guess there's different variations so there's there may be paths that you basically do get access if you have a web directory you drop your code in there and you're off and running um and then it's public so that's that's one um and that would be sort of geared towards someone who's a little more advanced yeah but some of the cloud providers are starting to market towards people who have no understanding i mean just an example we pointed out in our presentation um when we went to go sign up on the openshift or openshift account they basically had a little panel on the side that said um what is php you know like here's here's how you learn about php so yeah really gearing towards people who this is their first foray into you know cloud-based applications maybe application development in general yeah and so that's where that's what dangerous things can happen yeah you know that happens in in the other worlds where sure sure they read a book on how to code in you know php yeah and then they put out then they modify their resume and they get a job as a php developer after reading the 400 page book

This transcript was generated automatically from the video's captions and may contain errors.

Published: Mar 7, 2013
Updated: Jul 16, 2021
1 minute read

eSecurity Planet met up with Nicholas Percoco, senior VP at Trustwave SpiderlLabs, during the RSA conference last week to discuss the state of PaaS security. Percoco specifically took aim at the Red Hat OpenShift PaaS in his demo, though he cautioned that OpenShift is not necessarily vulnerable.

He noted that his team’s exploration into PaaS security did not discover or report any particular CVE-type vulnerability in OpenShift itself. But he argued that PaaS is sold and marketed to users as if they don’t have to worry about security — and that simply isn’t the case.

Read the full story at eSecurity Planet:
Is Cloud PaaS Safe?

Sean Michael Kerner is a senior editor at InternetNews.com, the news service of the IT Business Edge Network, the network for technology professionals Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

Internet News Logo

InternetNews is a source of industry news and intelligence for IT professionals from all branches of the technology world. InternetNews focuses on helping professionals grow their knowledge base and authority in their field with the top news and trends in Software, IT Management, Networking & Communications, and Small Business.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.