Meta
- “The slowest part of Amazon is the support”
- github search ‘mandatoryprogrammer’ ‘intruder’
- github search ‘mandatoryprogrammer’ ‘masscat’
- github search ‘moloch–’ ‘big rainbow’
People
- Mandatory - @iammandatory (Matthew Brian)
- Moloch - @littlejoetables
Burp intruder at PS
Cloud rainbow tables
Cost effective GPU clusters
“Burp Intruder” at infinate QPS
- (Burp proxy + replacement tags)
- Limitations - Threaded model, single app, single computer
- Use lambdas
- Self invocating lambda with a big array of work
- Their model just does a fan out
- 1k/s lambda second execution
Rainbow Tables
- Stick it into google big query
- generate the rainbow table, stick it into json blobs, put it into big query
- optimisations - base64 it or better encoding
- optimisations - truncate hash at 48bits (Collisions are not a huge concern)
Auto-scaling GPU clusters
- high upfront costs, etc
- Spot instances, elasticbeanstalk, lambda functions, api gateway, sqs, s3
- They give you a 2 minute warning before killing it
- beanstalk gives you EC2 instances and routes messages on queue
- “SpotPrice”