Post Syndicated from Explosm.net original https://explosm.net/comics/new-character
New Cyanide and Happiness Comic
Post Syndicated from Explosm.net original https://explosm.net/comics/new-character
New Cyanide and Happiness Comic
Post Syndicated from xkcd.com original https://xkcd.com/2842/

Post Syndicated from Curious Droid original https://www.youtube.com/watch?v=NI8HEbBhmWk
Post Syndicated from corbet original https://lwn.net/Articles/947825/
The 6.6-rc6 kernel prepatch is out for
testing. “So the previous week has been pretty calm, and a lot of the
”
discussion has been about future changes as so often happens late in the
release cycle.
Post Syndicated from corbet original https://lwn.net/Articles/947819/
The 6.1.58 stable kernel update has been
released; it consists mostly of a handful of reverts in the NFS subsystem.
Post Syndicated from Talks at Google original https://www.youtube.com/watch?v=wZPnWirAVVk
Post Syndicated from Eric Smith original https://www.servethehome.com/asus-expertcenter-pn64-e1-13th-gen-intel-core-mini-pc-mini-review/
In our ASUS ExpertCenter PN64-E1 review, we see how this Intel Core i5-13500H mini PC designed for corporate desktops compares
The post ASUS ExpertCenter PN64-E1 13th Gen Intel Core Mini PC Mini-Review appeared first on ServeTheHome.
Post Syndicated from Explosm.net original https://explosm.net/comics/signup
New Cyanide and Happiness Comic
Post Syndicated from Oglaf! -- Comics. Often dirty. original https://www.oglaf.com/loading/
Post Syndicated from Eric Smith original https://www.servethehome.com/8-port-2-5gbe-intel-core-virtualization-and-firewall-appliance-mini-review/
We recently took a look at two new 2.5GbE virtualization and firewall appliances. The first one was a 4-port 2.5GbE and 2-port 10GbE SFP+ system that we already reviewed. Now, we are taking a look at the 8-port 2.5GbE version of the system just to complete our review set. New 8-port 2.5GbE Intel Core Firewall […]
The post 8-port 2.5GbE Intel Core Virtualization and Firewall Appliance Mini-Review appeared first on ServeTheHome.
Post Syndicated from Geographics original https://www.youtube.com/watch?v=D1V8I9eSFXI
Post Syndicated from Techmoan original https://www.youtube.com/watch?v=99z6dBhONFc
Post Syndicated from Надежда Радулова original https://www.toest.bg/sedmitsata-9-14-oktomvri/

В края на миналата и началото на тази седмица за пореден път се оказахме изправени пред въпроса „Какво е Човекът?“. Венец на творението (по Софокъл) или въже над пропаст (по Ницше), уви, може би вече проядено, скъсано, продънено в пропастта. Чудо или чудовище е най-мощният проект на литературата, философията, изкуството, науката, технологиите?
Едва ли може да има бърз отговор на този въпрос – все още сме в ступор пред граничещите с немислимото картини на нечовешко насилие, извършено от човеци върху други човеци, в случая от бойците на радикалната организация „Хамас“ върху цивилни – деца и възрастни – в различни точки на Израел: от музикалния фестивал Supernova, събрал в пустинята младежи от различни страни, до кибуците Беери и Кфар Аза.
Как точно ще се развие конфликтът, чийто генезис все още е тема на разследване и анализ – дали наистина ще продължи да се разгръща в пълномащабна война, както прогнозират голяма част от специалистите по близкоизточните въпроси, или ще стихне временно… и кърваво и за двете страни? Дали главата на „Хамас“ ще бъде отсечена, а епидемията от терористични актове – овладяна, дали крайнодесните партии в управлението на Израел ще отстъпят от екстремистките си позиции, или още по-добре – ще бъдат извадени от властта, дали ще се поеме по някакъв път на мирни преговори за уреждане на десетилетния кръвопролитен конфликт между Израел и Палестина (с участието на останалите замесени в региона – Египет, Иран, Ливан и пр.) – предстои да узнаем в следващите дни и седмици.
Междувременно в новия ни брой ви припомняме, че преди по-малко от две години станахме свидетели на друго зверско клане, извършено от руските войници в Буча, Ирпин, Гостомел, Бородянка и още градове и села в Украйна. Човек ще рече, че насилието вдъхновява за още насилие, вместо да даде урок. За това как живеят днес оцелелите от сблъсъка с руските окупатори, може да прочетете във втория „репортаж“ от поредицата на Николета Атанасова „Откъси от Украйна: Сега идват зверовете“.
И докато през последните години „зверовете“ са във възход в нашата част от света – нещо, което бяхме позабравили, главозамаяни от европейската си „цивилизованост“, – по никакъв начин не можем да забравим, че след две седмици ни очакват местни избори. Най-малкото, ни го напомнят прясно пренаредените жълти павета, по които продължаваме да се препъваме, а автомобилите ни невротично подскачат като върху продънен батут. За изборите ни напомни и вялият радиодебат между двамата основни претенденти за кметското място в София. Ако сте готови за доза горчив смях или „смешен плач“ (по Ботев), прочетете анализа на Светла Енчева „Приспивен двубой. Липсващите теми в дебата между Васил Терзиев и Антон Хекимян“.
В предизборен контекст е добре да се чете и текстът на Емилия Милчева „За кого скачат синдикатите?“, в който прецизно се анализира политическата и корпоративната зависимост на профсъюзите у нас – разбира се, с акцент върху актуалните стачни действия на работещите във въгледобивната промишленост.
Съвсем очаквано, бедност, безизходица, престъпност, несполучила емиграция са темите на новото българско кино, представено на Варненския фестивал „Златна роза“. В повечето продукции мракът се сгъстява с всеки следващ сантиметър от лентата и „отникъде взорът надежда не види“. Дори и мотивът за непреходно-родното (под формата на патриотично-трапезен кич в някои от емигрантските сюжети) не може да вдъхне живот в оглозганата и притоплена тема за митарствата из мащехата чужбина. Повече за отличените продукции, сред които са безспорно силните „Уроците на Блага“, „Диада“ и „Васил“, ни разказва Петя Славова в „Българското кино на „Златна роза“ 2023“.
Ако искате за миг да се отърсите от мисълта за военните престъпления, за приближаващите избори и за смутната родна действителност, очевидно добре уловена в кинокадри, съветвам ви да прочетете последните вести, представени от Михаил Ангелов в „Научни новини: Нобелови награди 2023“. И без да разбирате от физика, химия или медицина, ще се уверите, че на този свят все пак има и хора, за които звездното небе над главите и моралният закон вътре в тях все още означават нещо.
Накрая искам да завърша седмичния преглед с една песен на Ленард Коен, личната му „молитва“, написана година след турнето му на фронта по време на Войната от Йом Кипур през 1973 г. – Who by Fire:
Кой от огън, кой във водата,
кой посред бял ден, кой в късна доба,
кой от съд божи, кой в съдебна зала, […]
кой окован във тъмница, кой на властта с наметалото,
кой, кой да кажа, че пита?“(прев. от английски Манол Пейков)
Текстът на песента носи отпечатъка на дните, прекарани от Ленард Коен сред войниците, но препраща и към молитвата „Унетане Токеф“, задължителна част от богослужението на Йом Кипур, Деня на изкуплението, деня на опрощаването на греховете. Дано тазгодишният Йом Кипур бъде последният, облян в кръв.
Post Syndicated from Blake Darché original http://blog.cloudflare.com/malicious-redalert-rocket-alerts-application-targets-israeli-phone-calls-sms-and-user-information/


On October 13, 2023, Cloudflare’s Cloudforce One Threat Operations Team became aware of a website hosting a Google Android Application (APK) impersonating the legitimate RedAlert – Rocket Alerts application (https://play.google.com/store/apps/details?id=com.red.alert&hl=en&pli=1). More than 5,000 rockets have been launched into Israel since the attacks from Hamas began on October 7th 2023. RedAlert – Rocket Alerts developed by Elad Nava allows individuals to receive timely and precise alerts about incoming airstrikes. Many people living in Israel rely on these alerts to seek safety – a service which has become increasingly important given the newest escalations in the region.
Applications alerting of incoming airstrikes have become targets as only days ago, Pro-Palestinian hacktivist group AnonGhost exploited a vulnerability in another application, “Red Alert: Israel” by Kobi Snir. (https://cybernews.com/cyber-war/israel-redalert-breached-anonghost-hamas/) Their exploit allowed them to intercept requests, expose servers and APIs, and send fake alerts to some app users, including a message that a “nuclear bomb is coming”. AnonGhost also claimed they attacked other rocket alert applications, including RedAlert by Elad Nava. As of October 11, 2023, the RedAlert app was reportedly functioning normally.
In the last two days, a new malicious website (hxxps://redalerts[.]me) has advertised the download of well-known open source application RedAlert by Elad Nava (https://github.com/eladnava/redalert-android). Domain impersonation continues to be a popular vector for attackers, as the legitimate website for the application (hxxps://redalert[.]me ) differs from the malicious website by only one letter. Further, threat actors continue to exploit open source code and deploy modified, malicious versions to unsuspecting users.
The malicious website hosted links to both the iOS and the Android version of the RedAlert app. But while the link to the Apple App Store referred to the legitimate version of the RedAlert app by Elad Nava, the link supposedly referring to the Android version hosted on the Play Store directly downloads a malicious APK file. This attack demonstrates the danger of sideloading applications directly from the Internet as opposed to installing applications from the approved app store.
The malicious RedAlert version imitates the legitimate rocket alert application but simultaneously collects sensitive user data. Additional permissions requested by the malicious app include access to contacts, call logs, SMS, account information, as well as an overview of all installed apps.
The website hosting the malicious file was created on October 12, 2023 and has since been taken offline. Only users who installed the Android version of the app from this specific website are impacted and urgently advised to delete the app. Users can determine if they installed the malicious version by reviewing the permissions granted to the RedAlert app. If users are unsure whether they installed the malicious version, they can delete the RedAlert applications and reinstall the legitimate version directly in the Play Store.

The malicious Android Package Kit (APK) file is installed by a user when they click the Google Play button on the fake RedAlert site. Once clicked, the user downloads the app directly from the fake site at hxxps://redalerts[.]me/app.apk. The SHA-256 hash of the APK is 5087a896360f5d99fbf4eb859c824d19eb6fa358387bf6c2c5e836f7927921c5.
A quick analysis of the AndroidManifest.xml file shows several differences compared to the legitimate, open source RedAlert application. Most notable are the additional permissions needed to collect information on the victim. The permissions added are listed below:
The application is designed to look and act like RedAlert. However, upon opening the app, a malicious service is started in the background. The startService() call is the only change to the onCreate() method, and this begins the sequence of malicious activity, which the actor has placed in a package called com.company.allinclusive.AI

The service is run to gather data from victims’ phones and upload it to the actor’s secure server. The data is extensive and includes:
The actor’s code for gathering this information is illustrated below.

Stolen data is uploaded to an HTTP server at a hardcoded IP address. The actor has a Tools class which details the IP address where the data is to be uploaded:

Although HTTP and port 80 are specified, the actor appears to have the ability to use HTTPS and port 443 if a certificate is found bundled within the application package:

Data is uploaded through a Connector class, written by the actor. The Connector is responsible for encrypting the stolen data and uploading it to the HTTP server. In this sample, files are encrypted with AES in CBC mode with PKCS5 Padding. The keys are randomly generated and appended to the packaged data, however the keys are encrypted with RSA using a public key bundled in the malicious app. Because of this, anybody who is able to intercept the stolen data will be unable to decrypt it without the actor’s private key.
The encrypted files have names that look like <ID>_<DATE>.final, which contain:
To avoid detection the actor included anti-analysis capabilities which can run at the time the app is started. The methods for anti-analysis that the attacker has included were anti-debugging, anti-emulation, and anti-test operations
The application makes a simple call using the builtin android.os.Debug package to see if the application is being debugged.

The application attempts to locate certain files and identifiers to determine whether it is being run in an emulated environment. A snippet of these indicators are shown below:

The application has utilities to identify whether a test user (“monkey”) is using the application:

These methodologies are all rudimentary checks for whether the application is under runtime analysis. It does not, however, protect the malicious code against static analysis.
If you have installed RedAlert on your device, the extraneous permissions added by the actor can be used to determine whether you have been compromised. The following permissions appearing on the RedAlert app (whether or not enabled) would indicate compromise:
You can avoid attacks like this by following the guidance below:
Under attack? Contact our hotline to speak with someone immediately.Visit 1.1.1.1 from any device to get started with our free app that makes your Internet faster and safer.To learn more about our mission to help build a better Internet, start here. If you’re looking for a new career direction, check out our open positions.
Post Syndicated from Explosm.net original https://explosm.net/comics/home-depot
New Cyanide and Happiness Comic
Post Syndicated from Bruce Schneier original https://www.schneier.com/blog/archives/2023/10/friday-squid-blogging-on-squid-intelligence.html
Article about squid intelligence.
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Read my blog posting guidelines here.
Post Syndicated from Eric Smith original https://www.servethehome.com/memblaze-pcie-gen5-nvme-ssds-at-fms-2023/
At FMS 2023, we saw the Memblaze PBlaze7 PCIe Gen5 NVMe SSDs and the higher-capcity PBlaze6 NVMe SSDs on the show floor
The post Memblaze PCIe Gen5 NVMe SSDs at FMS 2023 appeared first on ServeTheHome.
Post Syndicated from Christophe De La Fuente original https://blog.rapid7.com/2023/10/13/metasploit-weekly-wrap-up-31/

This week, contributor h00die added a module that leverages a prototype pollution bug in Kibana prior to version 7.6.3. Particularly, this issue is within the Upgrade Assistant and enables an attacker to execute arbitrary code. This vulnerability can be triggered by sending a queries that sets a new constructor.prototype.sourceURL directly to Elastic or by using Kibana to submit the same queries. Note that Kibana needs to be restarted or wait for collection to happen for the payload to execute. This vulnerability doesn’t seem to be assigned a CVE. The module has been written based on a detailed description from Alex Brasetvik (alexbrasetvik) in a Hackerone report.
Our very own zeroSteiner added a module that exploits PyTorch model server by chaining multiple vulnerabilities. First, it takes advantage of a weak default configuration that binds the management interface to all IP addresses. Then, once it reaches the management interface, the module exploits a Server-Side Request Forgery vulnerability (CVE-2023-43654) to register MAR (Model Archive) model files from arbitrary servers. Finally, it leverages a vulnerability in SnakeYaml (CVE-2022-1471) that allows code execution when a YAML file is deserialized by SnakeYaml. The module embeds a malicious YAML file in a MAR file and gets an arbitrary Java class executed when this MAR file is loaded.
Thanks to the work of Rory McKinley, multiple MySQL modules now support authentication against newer MySQL 8.0 versions. This required a lot of effort unearthing and patching historical code across multiple contributions to the Metasploit codebase, and to the Ruby MySQL library dependency. MySQL module highlights include:
auxiliary/scanner/mysql/mysql_login – Bruteforce and manual verification of MySQL credentialsauxiliary/scanner/mysql/mysql_version – MySQL Server Version Enumerationauxiliary/scanner/mysql/mysql_hashdump – MySQL password hashdump supportauxiliary/scanner/mysql/mysql_schemadump – Extracting MySQL schema detailsauxiliary/admin/mysql/mysql_sql – Run arbitrary MySQL SQL queries against a given targetAuthors: Alex Brasetvik (alexbrasetvik) and h00die
Type: Exploit
Pull request: #18417 contributed by h00die
Path: linux/http/kibana_upgrade_assistant_telemetry_rce
Description: Kibana before version 7.6.3 suffers from a prototype pollution bug within the Upgrade Assistant. By setting a new constructor.prototype.sourceURL value we’re able to execute arbitrary code in the context of the Kibana user. There is no CVE for this at the moment.
Authors: Gal Elbaz, Guy Kaplan, Idan Levcovich, Spencer McIntyre, and Swapneil Kumar Dash
Type: Exploit
Pull request: #18427 contributed by zeroSteiner
Path: multi/http/torchserver_cve_2023_43654
Description: This PR adds a module that exploits PyTorch TorchServer by chaining an SSRF vulnerability with a deserialization RCE vulnerability to permit an unauthenticated remote attacker arbitrary Java code execution. The PR also fixes how the ClassLoader mixin handles datastore options.
--defer-module-loads flag set. This also adds a new feature flag option defer_module_loads which, when enabled, will defer module loads by default without the need to specify--defer-module-loads every time the framework boots. Finally, this comes with a sizable improvement on frameworks boot up time.services -R command generated invalid hosts such as 192.0.2.2% if an empty string was registered for the scope metadata instead of nil.local and the remote IP is listed under remote.You can always find more documentation on our docsite at docs.metasploit.com.
As always, you can update to the latest Metasploit Framework with msfupdate
and you can get more details on the changes since the last blog post from
GitHub:
If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest.
To install fresh without using git, you can use the open-source-only Nightly Installers or the
binary installers (which also include the commercial edition).
Post Syndicated from The Hook Up original https://www.youtube.com/watch?v=Ef0tNjGDoOU
Post Syndicated from Rushabh Lokhande original https://aws.amazon.com/blogs/messaging-and-targeting/automate-marketing-campaigns-with-real-time-customer-data-using-amazon-pinpoint/
Amazon Pinpoint offers marketers and developers one customizable tool to deliver customer communications across channels, segments, and campaigns at scale. Amazon Pinpoint makes it easy to run targeted campaigns and drive customer communications across different channels: email, SMS, push notifications, in-app messaging, or custom channels. Amazon Pinpoint campaigns enables you define which users to target, determine which messages to send, schedule the best time to deliver the messages, and then track the results of your campaign.
In many cases, the customer data resides in a third-party system such as a CRM, Customer Data Platform, Point of Sales, database and data warehouse. This customer data represents a valuable asset for your organization. Your marketing team needs to leverage each piece of this data to elevate the customer experience.
In this blog post we will demonstrate how you can leverage users’ clickstream data stored in database to build user segments and launch campaigns using Amazon Pinpoint. Also, we will showcase the full architecture of the data pipeline including other AWS services such as Amazon RDS, AWS Data Migration Service, Amazon Kinesis and AWS Lambda.
Let us understand our case study with an example: a customer currently has digital touch points such as a Website and a Mobile App to collect the users’ clickstreams and behavioral data where they are storing them in a MySQL database. Marketing teams want to leverage the collected data to deliver a personalized experience by leveraging Amazon Pinpoint capabilities.
You can find below the detail of a specific use case covered by the proposed solution:
Please note that this use case is used to showcase the proposed solution capabilities. However, it is not limited to this specific use case since you can leverage any customer collected dimension/attribute to create specific campaign to achieve a specific marketing use case.
In this post, we provide a guided journey on how marketers can collect, segment, and activate audience segments in real-time to increase their agility in managing campaigns.
The use case covered in this post, focuses on demonstrating the flexibility offered by Amazon Pinpoint in both inbound (Ingestion) and outbound (Activation) stream of customer data. For the inbound stream, Amazon Pinpoint gives you a variety of ways to import your customer data, including:
We will focus on building a real-time inbound stream of customer data available within an Amazon RDS MySQL database specifically. It is important to mention that similar approach can be implemented to ingest data from third-party systems if any.
For the outbound stream, activating customer data using Amazon Pinpoint can be achieved using the following two methods:
The result of customer data activation cannot be completed without specifying the targeted channel. A channel represents the platform through which you engage your audience segment with messages. For example, Amazon Pinpoint customers can optimize how they target notifications to prospective customers through LINE message and email. They can deliver notifications with more information on prospected customer’s product information such as sales, new products etc. to the appropriate audience.
Amazon Pinpoint supports the following channels:
In addition to these channels, you can also extend the capabilities to meet your specific use case by creating custom channels. You can use custom channels to send messages to your customers through any service that has an API including third-party services. For example, you can use custom channels to send messages through third-party services such as WhatsApp or Facebook Messenger. We will focus on developing an Amazon Pinpoint connector using custom channel to target your customers on third-party services through API.
The below diagram illustrates the proposed architecture to address the use case. Moving from left to right:
Fig 1: Architecture Diagram for the Solution
Make sure that you complete the following steps as prerequisites:
npm install -g aws-cdk@latest
Step 1a: Open your device’s command line or Terminal.
Step1b: Checkout Git repository to a local directory on your device:
git clone https://github.com/aws-samples/amazon-pinpoint-realtime-campaign-optimization-example.git
Step 2: Change directories to the new directory code location:
cd amazon-pinpoint-realtime-campaign-optimization-example
Step 3: Update your AWS account number and region:
Fig 2: Configuring config.py for account-id and region
Fig 3: Configuring config.py for VPC and subnet information
Step 4: Verify if you are in the directory where app.py file is located:
ls -ltr app.py
Step 5: Create a virtual environment:
macOS/Linux:
python3 -m venv .env
Windows:
python -m venv .env
Step 6: Activate the virtual environment after the init process completes and the virtual environment is created:
macOS/Linux:
source .env/bin/activate
Windows:
.env\Scripts\activate.bat
Step 7: Install the required dependencies:
pip3 install -r requirements.txt
Step 8: Bootstrap the cdk app using the following command:
cdk bootstrap aws://<AWS_ACCOUNTID>/<AWS_REGION>
Replace the place holder AWS_ACCOUNTID and AWS_REGION with your AWS account ID and the region to be deployed.
This step provisions the initial resources, including an Amazon S3 bucket for storing files and IAM roles that grant permissions needed to perform deployments.
Fig 4: Bootstrapping CDK environment
Please note, if you have already bootstrapped the same account previously, you cannot bootstrap account, in such case skip this step or use a new AWS account.
Step 9: Make sure that your AWS profile is setup along with the region that you want to deploy as mentioned in the prerequisite. Synthesize the templates. AWS CDK apps use code to define the infrastructure, and when run they produce or “synthesize” a CloudFormation template for each stack defined in the application:
cdk synthesize
Step 10: Deploy the solution. By default, some actions that could potentially make security changes require approval. In this deployment, you’re creating an IAM role. The following command overrides the approval prompts, but if you would like to manually accept the prompts, then omit the –require-approval never flag:
cdk deploy "*" --require-approval never
While the AWS CDK deploys the CloudFormation stacks, you can follow the deployment progress in your terminal.
Fig 5: AWS CDK Deployment progress in terminal
Once the deployment is successful, you’ll see the successful status as follows:
Fig 6: AWS CDK Deployment completion success
Step 11: Log in to the AWS Console, go to CloudFormation, and see the output of the ApplicationStack:
Fig 7: AWS CloudFormation stack output
Note the values of PinpointProjectId, PinpointProjectName, and RDSSecretName variables. We’ll use them in the next step to upload our artifacts
In this section we will create a full data flow using the below steps:
Step 1: Connect to MySQL DB instance and create customer database
sudo yum update -y
sudo yum install -y mysql
mysql -h <<host>> -P 3308 --user=<<username>> --password=<<password>>
Welcome to the MariaDB monitor. Commands end with ; or \g.
Your MySQL connection id is 27
Server version: 8.0.32 Source distribution
Copyright (c) 2000, 2018, Oracle, MariaDB Corporation Ab and others.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
MySQL [(none)]>
Step 2: Ingest data in the customer_tb table within the Amazon RDS MySQL DB instance Once the connection to the MySQL DB instance established, using the same AWS Cloud9 Linux shell connected to the MySQL RDS DB execute following commands.
CREATE DATABASE `pinpoint-test-db`;
Use `pinpoint-test-db`;
CREATE TABLE `customer_tb` (`userid` int NOT NULL,
`email` varchar(150) DEFAULT NULL,
`language` varchar(45) DEFAULT NULL,
`favourites` varchar(250) DEFAULT NULL,
PRIMARY KEY (`userid`);
DESCRIBE `pinpoint-test-db`.customer_tb;
Fig 8: Verify schema for customer_db table
Use `pinpoint-test-db`;
insert into customer_tb values (1,'[email protected]','english','football');
insert into customer_tb values (2,'[email protected]','english','basketball');
insert into customer_tb values (3,'[email protected]','french','football');
insert into customer_tb values (4,'[email protected]','french','football');
insert into customer_tb values (5,'[email protected]','french','basketball');
insert into customer_tb values (6,'[email protected]','french','football');
insert into customer_tb values (7,'[email protected]','french',null);
insert into customer_tb values (8,'[email protected]','english','football');
insert into customer_tb values (9,'[email protected]','english','football');
insert into customer_tb values (10,'[email protected]','english',null);
select * from `pinpoint-test-db`.`customer_tb`;
Fig 9: Verify data for customer_db table
Step 3: Validate that AWS Data Migration Service created task is replicating the changes to the Amazon Kinesis Data Streams
Fig 10: Starting AWS DMS Replication Task
Fig 11: AWS DMS Replication statistics
Fig 12: AWS DMS Replication statistics
Step 4: Validate that endpoints are created within Amazon Pinpoint
Fig 13: Amazon Pinpoint endpoint summary
Step 5: Create Amazon Pinpoint Segment and Campaign
Step 5.1: Create Amazon Pinpoint Segment
Fig 14: Amazon Pinpoint segment summary
Step 5.2: Create Amazon Pinpoint Campaign
Fig 15: Amazon Pinpoint create campaign
Fig 16: Amazon Pinpoint segment
Fig 17: Amazon Pinpoint message creation
Fig 18: Amazon Pinpoint campaign scheduling
If you push more messages or records into Amazon RDS (from step 2.4), you will need to create a new campaign (from step 4.2) to process the new messages.
Fig 19: Amazon Pinpoint campaign processing status
Fig 20: Amazon Pinpoint campaign metrics
This is a quick summary of what we accomplished:
You have now gained a good understanding of Amazon Pinpoint agnostic data flow but there are still many areas left for exploration. What this workshop hasn’t covered is the operation of other communication channels such as Email, SMS, Push notification and Voice outbound. You can enable the channels that are pertinent to your use case and send messages using campaigns or journeys.
Make sure that you clean up all of the other AWS resources that you created in the AWS CDK Stack deployment. You can delete these resources via the AWS CDK Destroy command as follows or the CloudFormation console.
To destroy the resources using AWS CDK, follow these steps:
cdk destroy
In this post, you have now gained a good understanding of Amazon Pinpoint flexible real-time data flow. By implementing the steps detailed in this blog post, you can achieve a seamless integration of your customer data from Amazon RDS MySQL database to Amazon Pinpoint where you can leverage segments and campaigns to activate data using custom channels to third-party services via API. The demonstrated use case focuses on Amazon RDS MySQL database as a data source. However, there are still many areas left for exploration. What this post hasn’t covered is the operation of integrating customer data from other type of data sources such as MongoDB, Microsoft SQL Server, Google Cloud, etc. Also, other communication channels such as Email, SMS, Push notification and Voice outbound can be used in the activation layer. You can enable the channels that are pertinent to your use case and send messages using campaigns or journeys, and get a complete view of their customers across all touchpoints and can lead to less relevant marketing campaigns.
![]() |
Bret Pontillo is a Senior Data Architect with AWS Professional Services Analytics Practice. He helps customers implement big data and analytics solutions. Outside of work, he enjoys spending time with family, traveling, and trying new food. |
![]() |
Rushabh Lokhande is a Data & ML Engineer with AWS Professional Services Analytics Practice. He helps customers implement big data, machine learning, and analytics solutions. Outside of work, he enjoys spending time with family, reading, running, and golf. |
![]() |
Ghandi Nader is a Senior Partner Solution Architect focusing on the Adtech and Martech industry. He helps customers and partners innovate and align with the market trends related to the industry. Outside of work, he enjoys spending time cycling and watching formula one. |