community • The most frequent question is, “I knock the metadata API, but can’t understand anything there.” • False confidence in AWS being vulnerable to nothing but public S3 and SSRF to metadata API. • Curiosity 3
A ready virtual server • Equipped with virtual metadata API • May be furnished with a user data script • A part of the AWS ecosystem. • Connected to VPC
code execution. The code in it is executed for data processing, big data, etc. We post python code in a website form → the code is parsed and ran on AWS Lambda. AWS Lambda
action. It serves 4 major tasks: 1. To block all tcp connections (udp aren’t blocked) 2. Restrict all child processes 3. Forbids read/write to tmp 4. Forbids reading a handler script that contains the biggest amount of code AWS Lambda
Raynor's privileges and notices the SetDefaultPolicyVersion permission - allowing access to 4 other versions of the policy via setting an old version as the default. CloudGoat Escalation case
step, the attacker may choose to revert Raynor's policy version back to the original one, thereby concealing their actions and the true capabilities of the IAM user. CloudGoat Escalation case
IAM user "Raynor," the attacker has only a few limited - seemingly harmless - privileges available to them. 2. The attacker analyzes Raynor's privileges and notices the SetDefaultPolicyVersion permission - allowing access to 4 other versions of the policy via setting an old version as the default. 3. After reviewing the old policy versions, the attacker finds that one version in particular offers a full set of admin rights. 4. Attacker restores the full-admin policy version, gaining full admin privileges and the ability to carry out any malicious actions they wish. 5. As a final step, the attacker may choose to revert Raynor's policy version back to the original one, thereby concealing their actions and the true capabilities of the IAM user. CloudGoat Escalation case
a couple of helpful links! • https://github.com/RhinoSecurityLabs/AWS- IAM-Privilege-Escalation - 28 (!!!) techniques • https://github.com/RhinoSecurityLabs/pacu - метасплоит мира AWS AWS IAM
AWS Managed Policies can be attached to the principal used to run Scout in order to grant the necessary permissions: • ReadOnlyAccess • SecurityAudit You will also find a custom policy to run Scout with minimal privileges here.
users in your AWS account. The purpose of the service: • Obtain identity ID • Pass AWS Credentials The service is used by mobile apps and websites AWS cognito
Keys Now WhatTaking the Pen Test Into the Amazon Cloud Jim Shave https://www.youtube.com/watch?v=vV7xN2JQNOU • Finding Secrets In Publicly Exposed EBS Volumes - Ben Morris https://www.youtube.com/watch?v=-LGR63yCTts • CloudGoat https://github.com/RhinoSecurityLabs/cloudgoat • Blog RhinoSecurity https://rhinosecuritylabs.com/blog/ • Blog Andres Riancho https://andresriancho.com/blog