Aws Allow All Egress
Description
Detects AWS Network Access Control Lists (NACLs) that have overly permissive outbound rules allowing unrestricted egress traffic. Unrestricted outbound access could enable compromised resources to exfiltrate data or communicate with malicious actors.
Detection Strategy
• Examines each Network ACL's outbound rules in the specified AWS region
• Reports a vulnerability if a NACL rule allows outbound traffic (egress) to all destinations (0.0.0.0/0)
• Evaluates all Network ACLs associated with VPCs in the account for compliance with egress traffic restrictions
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan.If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.