avatarTeri Radichel

Free AI web copilot to create summaries, insights and extended knowledge, download it at here

3236

Abstract

<iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FKoVpJDZPvms&amp;display_name=YouTube&amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DKoVpJDZPvms&amp;image=http%3A%2F%2Fi.ytimg.com%2Fvi%2FKoVpJDZPvms%2Fhqdefault.jpg&amp;key=a19fcc184b9711e1b4764040d3dc5c07&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="640"> </div> </div> </figure></iframe></div></div></figure><p id="8453">This is a song that MOCKS both <i>Hey Joe</i> and <i>Wild Thing</i>. I take Hendrix seriously, but maybe at times like these we all have to be willing to laugh at what we hold sacred.</p><h2 id="3fdc">BBC Said I Was Right</h2><p id="a0a7">Last night I was listening to BBC overnight and they excerpted at WNYC interview with Moon Unit Zappa and Thorsten Schütte, who have just released a Documentary on Zappa called <a href="http://www.sundance.org/projects/eat-that-question-frank-zappa-in-his-own-words">“<i>Eat that Question: Frank Zappa in His Own Words</i></a><i>.</i>” Why would the Universe, the BBC, and WNYC all point me to Zappa if Zappa wasn’t the answer?</p><div id="33c5" class="link-block"> <a href="http://www.wnyc.org/story/frank-zappa-his-own-words/"> <div> <div> <h2>Moon Unit Zappa on Her Father's Music and Public Persona</h2> <div><h3>Veteran filmmaker Thorsten Schütte talks about his new documentary "Eat that Question: Frank Zappa in His Own Words,…</h3></div> <div><p>www.wnyc.org</p></div> </div> <div> <div style="background-image: url(https://miro.readmedium.com/v2/resize:fit:320/0*WNXayGNoGVDHwndt.)"></div> </div> </div> </a> </div><h2 id="dd75">There Are Many Reasons to Like Zappa, but I Like Him Because He is Obscenely Funny</h2><p id="7331">He was onto dude bros before dude bros were called dude bros:</p> <figure id="0e3d"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FZUq_T_Bhau8%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DZUq_T_Bhau8&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FZUq_T_Bhau8%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="640"> </div> </div> </figure></iframe></div></div></figure><p id="eab9">Maybe before we try to “Make America Great Again” we should re-listen to Zappa’s screed against unions in California and the shortcomings of American manufacturing.</p> <figure id="b307"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FjKE3ZLj7_V8%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DjKE3ZLj7_V8&amp;image=htt # Options ps%3A%2F%2Fi.ytimg.com%2Fvi%2FjKE3ZLj7_V8%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="640"> </div> </div> </figure></iframe></div></div></figure><p id="3481">Thanks to the Internet, we can watch Frank work:</p> <figure id="f69e"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-7nB4trlCzI%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-7nB4trlCzI&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-7nB4trlCzI%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="854"> </div> </div> </figure></iframe></div></div></figure><p id="bd7f">Zappa could also play guitar:</p> <figure id="93bd"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F-Jh6wnmRbvQ%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D-Jh6wnmRbvQ&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F-Jh6wnmRbvQ%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="640"> </div> </div> </figure></iframe></div></div></figure><p id="b44d">He could even make Yoko Ono fun:</p> <figure id="12d0"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F3auiYaRw2WU%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D3auiYaRw2WU&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F3auiYaRw2WU%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="854"> </div> </div> </figure></iframe></div></div></figure><h2 id="698c">Zappa Will Cheer You Up</h2><p id="c418">Listen to this cover of <i>I am the Walrus.</i></p> <figure id="a378"> <div> <div> <img class="ratio" src="http://placehold.it/16x9"> <iframe class="" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2FpZDR1ALvkVQ%3Ffeature%3Doembed&amp;url=http%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3DpZDR1ALvkVQ&amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2FpZDR1ALvkVQ%2Fhqdefault.jpg&amp;key=d04bfffea46d4aeda930ec88cc64b87c&amp;type=text%2Fhtml&amp;schema=youtube" allowfullscreen="" frameborder="0" height="480" width="640"> </div> </div> </figure></iframe></div></div></figure><p id="92c6">Where are your troubles now, America?</p></article></body>

Ambiguous Error Message When a User Doesn’t Have Permission to Pass a Specific IAM Role to an EC2 Instance

This error message needs to be more specific and doesn’t show up in CloudTrail for the User Name

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

⚙️ Check out my series on Automating Cybersecurity Metrics | Code.

🔒 Related Stories: Bugs | AWS Security | AWS EC2 Troubleshooting

💻 Free Content on Jobs in Cybersecurity | ✉️ Sign up for the Email List

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

I was trying to launch an EC2 instance with a specific role for the EC2 instance profile, but I had a typo in the IAM role for the user.

The error message comes back as encoded so I needed to first decode it as explained here:

Once I decoded the message this is what I get:

aws sts decode-authorization-message --encoded-message "$msg" --output text --profile SandboxAdmin

{"allowed":false,"explicitDeny":false,"matchedStatements":{"items":[]},"failures":{"items":[]},"context":{"principal":{"id":"","name":"SandboxDev","arn":"arn:aws:iam::xxxxxxxxxxxx:user/SandboxDev"},"action":"RunInstances","resource":"arn:aws:iam::xxxxxxxxxxxx:role/SandboxDevEC2Role","conditions":{"items":[{"key":"aws:Region","values":{"items":[{"value":"us-east-2"}]}},{"key":"aws:Service","values":{"items":[{"value":"ec2"}]}},{"key":"aws:Resource","values":{"items":[{"value":"role/SandboxDevEC2Role"}]}},{"key":"iam:RoleName","values":{"items":[{"value":"SandboxDevEC2Role"}]}},{"key":"aws:Type","values":{"items":[{"value":"role"}]}},{"key":"aws:Account","values":{"items":[{"value":"xxxxxxxxxxxx"}]}},{"key":"aws:ARN","values":{"items":[{"value":"arn:aws:iam::xxxxxxxxxxxxx:role/SandboxDevEC2Role"}]}}]}}}

That is not at all clear. I looked at it and thought my user did not have permission to perform the RunInstances action based on that message, but the user did have permission.

Somehow I just guessed that the role must be the problem and figured it out.

First of all, why does this have to be encoded? Shouldn’t AWS be able to display a nice, easy to read, error message in this case and pinpoint the problem?

Also, when I went over to look at CloudTrail, I searched on the user name. I did not see the RunInstances failure in the logs initially. It seemed to take a long time to show up. When it did, it was just the same message above.

Follow for updates.

Teri Radichel | © 2nd Sight Lab 2023

About Teri Radichel:
~~~~~~~~~~~~~~~~~~~~
⭐️ Author: Cybersecurity Books
⭐️ Presentations: Presentations by Teri Radichel
⭐️ Recognition: SANS Award, AWS Security Hero, IANS Faculty
⭐️ Certifications: SANS ~ GSE 240
⭐️ Education: BA Business, Master of Software Engineering, Master of Infosec
⭐️ Company: Penetration Tests, Assessments, Phone Consulting ~ 2nd Sight Lab
Need Help With Cybersecurity, Cloud, or Application Security?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
🔒 Request a penetration test or security assessment
🔒 Schedule a consulting call
🔒 Cybersecurity Speaker for Presentation
Follow for more stories like this:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
❤️ Sign Up my Medium Email List
❤️ Twitter: @teriradichel
❤️ LinkedIn: https://www.linkedin.com/in/teriradichel
❤️ Mastodon: @teriradichel@infosec.exchange
❤️ Facebook: 2nd Sight Lab
❤️ YouTube: @2ndsightlab
Error Message
Ec2
Iam
Permission
Assume Role
Recommended from ReadMedium