설명
짧거나 쉽게 예측할 수 있는 IAM 콘솔 비밀번호는 추측 공격에 취약할 수 있습니다. 길이를 늘리더라도 재사용하거나 널리 알려진 비밀번호라면 적절한 보호가 되지 않습니다.
잠재적 영향
비밀번호가 추측되면 계정에 부여된 권한이 악용될 수 있습니다.
해결 방법
조직의 길이 기준에 맞는 고유한 비밀번호를 사용하고 MFA를 적용하세요. 최소 14자를 기준으로 삼는다면 그 이상을 요구하도록 계정 비밀번호 정책을 설정하세요.
예시
길이 차이만 보여 주는 예시입니다. 표시된 비밀번호는 실제 계정에 사용하지 말고, 운영 비밀번호는 안전한 입력이나 비밀 관리 경로로 전달하세요. 참조 리소스는 생략했습니다.
변경 전
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: 비밀번호 길이 비교 예시
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
LoginProfile:
Password: myP@ssW0rd
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
- PolicyName: giveaccesstotopiconly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sns:*
Resource:
- !Ref mytopic
- Effect: Deny
Action:
- sns:*
NotResource:
- !Ref mytopic
변경 후
yaml
AWSTemplateFormatVersion: "2010-09-09"
Description: 비밀번호 길이 비교 예시
Resources:
myuser:
Type: AWS::IAM::User
Properties:
Path: "/"
LoginProfile:
Password: myP@ssW0rd123asw
Policies:
- PolicyName: giveaccesstoqueueonly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sqs:*
Resource:
- !GetAtt myqueue.Arn
- Effect: Deny
Action:
- sqs:*
NotResource:
- !GetAtt myqueue.Arn
- PolicyName: giveaccesstotopiconly
PolicyDocument:
Version: '2012-10-17'
Statement:
- Effect: Allow
Action:
- sns:*
Resource:
- !Ref mytopic
- Effect: Deny
Action:
- sns:*
NotResource:
- !Ref mytopic