Cloud Penetration Testing

  • LaBarge R
N/ACitations
Citations of this article
26Readers
Mendeley users who have this article in their library.

Abstract

This paper presents the results of a series of penetration tests performed on the OpenStack Essex Cloud Management Software. Several different types of penetration tests were performed including network protocol and command line fuzzing, session hijacking and credential theft. Using these techniques exploitable vulnerabilities were discovered that could enable an attacker to gain access to restricted information contained on the OpenStack server, or to gain full administrative privileges on the server. Key recommendations to address these vulnerabilities are to use a secure protocol, such as HTTPS, for communications between a cloud user and the OpenStack Horizon Dashboard, to encrypt all files that store user or administrative login credentials, and to correct a software bug found in the OpenStack Cinder type-delete command.

Cite

CITATION STYLE

APA

LaBarge, R. (2012). Cloud Penetration Testing. International Journal on Cloud Computing: Services and Architecture, 2(6), 43–62. https://doi.org/10.5121/ijccsa.2012.2604

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free