Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cloud Security

Thousands of Apps Using AWS ALB Exposed to Attacks Due to Configuration Issue

As many as 15,000 applications using AWS Application Load Balancer (ALB) could be exposed to ALBeast attacks. 

As many as 15,000 apps that use AWS’s Application Load Balancer (ALB) for authentication could be vulnerable to attacks, according to application security company Miggo.

These attacks, dubbed ALBeast by Miggo, are possible due to what the company has described as a critical configuration issue, rather than an actual vulnerability in the AWS ALB solution. 

AWS ALB is a load balancer that routes traffic to EC2 instances, containers, IP addresses, and Lambda functions based on the content of the request.

AWS was informed about the potential risks in April and it has since updated its documentation and added new code to help customers prevent ALBeast attacks, Miggo said.

A Censys search reveals over 370,000 internet-exposed instances of AWS ALB. Miggo has determined that over 15,000 of them may be vulnerable due to a configuration issue. However, the company noted that even apps that are not exposed to the internet may be targeted by attackers who have network access. 

“First, the attacker creates their own ALB instance with authentication configured in their account. The attacker then uses this ALB to sign a token they fully control. Next, the attacker alters the ALB configuration and sets the issuer field to the victim’s expected issuer,” Miggo explained.

Advertisement. Scroll to continue reading.

“AWS subsequently signs the attacker’s forged token with the victim’s issuer. Finally, the attacker uses this minted token against the victim’s application, bypassing both authentication and authorization,” it added.

According to Miggo, an ALBeast attack can enable threat actors to gain unauthorized access to business resources and exfiltrate data. 

Users can prevent attacks by ensuring that apps using ALB authentication check the token signer, and by ensuring that only traffic from their ALB is accepted. 

Responding to a SecurityWeek inquiry, an AWS spokesperson stated, “It is incorrect to call this an authentication and authorization bypass of AWS Application Load Balancer (ALB) or any other AWS service because the technique relies on a bad actor already having direct connectivity to a misconfigured customer application that does not authenticate requests. We recommend customers configure their applications to only accept requests from their ALB by using security groups and by following the ALB security best practices.”

Regarding the number of potentially impacted applications, the AWS representative noted, “A small fraction of a percent of AWS customers have applications potentially misconfigured in this way, significantly fewer than the researchers’ estimate. We have contacted each one of these customers directly to share best practices for configuring applications which use ALB.”

*updated with statement from AWS

Related: Cloud Users Warned of Data Exposure Risk From Command-Line Tools

Related: Azure Health Bot Service Vulnerabilities Possibly Exposed Sensitive Data

Related: Vulnerability Allowed Takeover of AWS Apache Airflow Service

Related: SAP AI Core Vulnerabilities Allowed Service Takeover, Customer Data Access

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.