跳到正文
原文
Unit 42· Niv Rabin·· 13 天前精选关注度78

Unit 42 披露 AWS AgentCore Harness 默认配置下凭据可被提示注入窃取

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

AI 导读

Unit 42 发现 AWS AgentCore Harness 默认开启的内置 shell 工具以 root 运行,且与解析凭据的运行时同处一个进程,攻击者可通过间接提示注入读取 /proc/1/mem,从堆内存中提取 AgentCore Identity 保管的明文 JWT。

推荐理由

原文完整还原了从间接提示注入到读取进程内存、外泄 JWT 并重放取 PII 的链路,部署 Agent 运行时的团队可据此检查 shell 工具与凭据解析是否同处一个进程。

阅读原文unit42.paloaltonetworks.com