Riyaz Walikar (@riyazwalikar) 's Twitter Profile
Riyaz Walikar

@riyazwalikar

Break. Fix. Repeat.
Co-founder/Chief Hacker @Kloudleinc

#CloudNative #CloudSecurity #AWSSecurity #GCPSecurity #AzureSecurity

ID: 34319769

linkhttp://ibreak.software/ calendar_today22-04-2009 16:34:04

2,2K Tweet

5,5K Followers

958 Following

Rohit Jadav (@saucyvip3r) 's Twitter Profile Photo

We successfully completed the cloud security training at NULLCON Thanks to Riyaz Walikar for all the guidence and Appsecco team for all the support #AppseccoAtNullcon #Nullcon #appsecco #cloudsecurity #aws #gcp #infosec

We successfully completed the cloud security training at <a href="/nullcon/">NULLCON</a> 
Thanks to <a href="/riyazwalikar/">Riyaz Walikar</a> for all the guidence and <a href="/appseccouk/">Appsecco</a> team for all the support
#AppseccoAtNullcon #Nullcon #appsecco #cloudsecurity #aws #gcp #infosec
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

AWS Roles Anywhere allows non #AWS workloads to obtain tmp security credentials in IAM. Here's a step by step guide. #awscloud #cloudsecurity

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

I'll be performing magic on air and talking about a business that collapsed due to a cloud misconfiguration that was exploited. From Success to Nightmare: The story of a cloud misconfig that destroyed a business Feb 16th 12:30 PM IST forms.gle/roWR54M27XyUjY… cc:Kloudle - Cloud Security Scanner

I'll be performing magic on air and talking about a business that collapsed due to a cloud misconfiguration that was exploited. 

From Success to Nightmare: The story of a cloud misconfig that destroyed a business

Feb 16th 12:30 PM IST

forms.gle/roWR54M27XyUjY…

cc:<a href="/Kloudleinc/">Kloudle - Cloud Security Scanner</a>
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

If you missed my last tweet, I'll be performing magic on air and talking about a business that collapsed due to a cloud misconfiguration that was exploited, in my upcoming webinar. Limited seats! Feb 16th 12:30 PM IST forms.gle/roWR54M27XyUjY… cc:Kloudle - Cloud Security Scanner #cloudsecurity

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

Webinar Alert! Register if u haven’t already. Registered folks get webinar joining deets. WeAreSecure Fake Inc.'s story of a AWS misconfig that led to their collapse. Also, my first attempt at doing magic on air!😊 Feb 16th 12:30 PM IST forms.gle/roWR54M27XyUjY… cc:Kloudle - Cloud Security Scanner

Webinar Alert! Register if u haven’t already. Registered folks get webinar joining deets.

WeAreSecure Fake Inc.'s story of a AWS misconfig that led to their collapse.

Also, my first attempt at doing magic on air!😊

Feb 16th 12:30 PM IST

forms.gle/roWR54M27XyUjY…

cc:<a href="/Kloudleinc/">Kloudle - Cloud Security Scanner</a>
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

Come hear me talk about abusing misconfigurations in #awscloud at nullDubai on 16th March. Some horror stories and friendly banter at the meetup. Location and announcement coming up soon Rupam Bhattacharya TAS #null #cloudsecurity

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

Anyone else notice the #AWS Console Sign-In asks for MFA token even if you provided an incorrect password, while the username and password was received and processed in the first request. I find that strange 🙃

Anyone else notice the #AWS Console Sign-In asks for MFA token even if you provided an incorrect password, while the username and password was received and processed in the first request.

I find that strange 🙃
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

TIL that Session Tokens in #AWS from the Global STS endpoint (sts.amazonaws.com) are valid only in regions that are enabled by default. For new enabled regions use regional sts endpoints or change this option under IAM settings. #cloudsecurity

TIL that Session Tokens in #AWS from the Global STS endpoint (sts.amazonaws.com) are valid only in regions that are enabled by default.

For new enabled regions use regional sts endpoints or change this option under IAM settings.

#cloudsecurity
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

Limited seats only! I'll be doing a 2 day in person hands-on cloud security training titled "Breaking and Pwning Apps and Servers on #AWS and #GoogleCloud" Security BSides Bangalore on June 6th-7th. Register now! bsidesbangalore.in/event-details/2 cc Appsecco Kloudle - Cloud Security Scanner

Limited seats only! I'll be doing a 2 day in person hands-on cloud security training titled "Breaking and Pwning Apps and Servers on #AWS and #GoogleCloud" <a href="/bsidesbangalore/">Security BSides Bangalore</a> on June 6th-7th. Register now!

bsidesbangalore.in/event-details/2

cc <a href="/appseccouk/">Appsecco</a> <a href="/Kloudleinc/">Kloudle - Cloud Security Scanner</a>
Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

We have opened special registration for Session 6 of the ongoing #AWS Security #Masterclass. Limited seats only for this mini hackathon/CTF. Link for registration - kloudle.com/masterclass/ Registrations will close on capacity! #CloudSecurity

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

The wait is over! We have now released the content for Session 1 to Session 6 of the ongoing #AWS Security #Masterclass. Go to kloudle.com/masterclass now! Content for Session 7 - 10 will be released after the Masterclass is over. Subscribe to get notified! #cloudsecurity

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

We did some analysis of a recent research post where the author claimed to have found 2 #AWS #EKS 0 Days with significant risks to thousands of clusters. Our analysis showed that the claims were simply a result of how AWS EKS is designed. kloudle.com/blog/refuting-… #kubernetes

Riyaz Walikar (@riyazwalikar) 's Twitter Profile Photo

I fondly remember my first #kubernetes cluster pentest several years ago. Gained cluster admin by reading protected credentials using a binary planting/path confusion bug! Fun times! 😎 🎊 I'm running a poll to know who in my connections is using Kubernetes in prod?