SlideShare a Scribd company logo
1 of 43
Download to read offline
Attacking AWS: the
full cyber kill chain
Pawel Rzepa
www.securing.biz
#whoami
• Senior Security Consultant in
- Pentesting
- Cloud security assessment
• Blog: https://medium.com/@rzepsky
• Twitter: @Rzepsky
www.securing.biz
VS
www.securing.biz
source: https://redlock.io/blog/cryptojacking-tesla
www.securing.biz
source: https://www.bloomberg.com/news/articles/2017-11-21/uber-
concealed-cyberattack-that-exposed-57-million-people-s-data
www.securing.biz
www.securing.biz
www.securing.biz
Somewhere in the other
end of the Internet...
Demo: https://vimeo.com/334855817
www.securing.biz
Domainanalytics.online intro
Identify the IP owner
www.securing.biz
Public AWS IP ranges: https://amzn.to/2EbvP0J
Or use AWS EC2 reachability test: https://bit.ly/30274Ag
www.securing.biz
Demo: https://vimeo.com/334856068
www.securing.biz
Exploiting SSRF
Demo: https://vimeo.com/334856278
www.securing.biz
Ooops… other services are also available!
What is metadata?
• Data about your instance
• It's a link-local address, accessible ONLY from
your instance!
• May include access keys to Instance Profile:
www.securing.biz
http://169.254.169.254/latest/meta-data/iam/security-credentials/
http://169.254.169.254/latest/meta-data/
www.securing.biz
ports 1-65535
from 0.0.0.0/0
webserver_role
www.securing.biz
Demo: https://vimeo.com/334856214
www.securing.biz
Pacu intro
www.securing.biz
Enumerate permissions
www.securing.biz
You need the following permissions to display your permissions:
iam:ListAttachedUserPolicies
iam:GetUserPolicy
...little chances to see them in Instance Profile :/
Bruteforce permissions
www.securing.biz
Enumerate, enumerate, enumerate!
Pacu (Domain Analytics:ec2_pivot) > run ec2__enum
(...)
Pacu (Domain Analytics:ec2_pivot) > data EC2
(...)
VS
www.securing.biz
There's a stopped instance (i-08d6cf0eaf210a552)
with instance-profile/admin attached!
www.securing.biz
What can we find out there?
www.securing.biz
ports 1-65535
from 0.0.0.0/0
webserver_role
admin
Demo: https://vimeo.com/334856098
www.securing.biz
Privilege escalation
www.securing.biz
#cloud-boothook
www.securing.biz
ports 1-65535
from 0.0.0.0/0
SSRF/RCE
admin
User
Data
reverse shell
getting administrator access
webserver_role
Staying under the hoodStaying under the hood
CloudTrail by default monitors all regions
CloudTrail: ways to hide your fingerprints
Persist access
• Bind shell in User Data with backdoor in Security
Groups
• Lambda backdoor which creates IAM user when
specific CloudWatch Event occurs)
• Add extra keys to existing user
www.securing.biz
Demo: https://vimeo.com/334856167
www.securing.biz
Without monitoring it’s hard to detect a 2nd
key pair… even for legit administrator :O
Let's switch perspective to the blue team
www.securing.biz
Analysing what went wrong
• Vulnerable, publicly available web application
• "Test" instance with admin permissions (possible
privilege escalation)
• Missing monitoring services of sensitive actions (e.g.
using Instance Profile's keys outside the instance,
modifying CloudTrail's settings, creating additional keys
etc.)
• Improperly configured CloudTrail Service (missing log
encryption, missing log replication to the bucket under
different AWS account) as well as Security Groups
www.securing.biz
• Are there any extra,
undocumented resources?
• Is the system architecture
free from design flaws?
Cloud security assessment: architecture review
www.securing.biz
Cloud security assessment: configuration review
• Are all cloud services
configured in compliance
with best practices?
www.securing.biz
• Are your applications free
from vulnerabilities like
RCE/SSRF/XXE etc.?
• Is the Serverless code
secure (e.g. free from
"event injections")?
Cloud security assessment: pentesting sensitive services
www.securing.biz
• Do you monitor sensitive
actions?
• Do you have defined
incident response
procedure?
Cloud security assessment: verifying monitoring processes
www.securing.biz
Cloud security assessment in practice
• Vulnerable, publicly available web application
• "Test" instance with admin permissions (possible
privilege escalation)
• Missing monitoring services of sensitive actions (e.g.
using Instance Profile's keys outside the instance,
modifying CloudTrail's settings, creating additional
keys etc.)
• Improperly configured CloudTrail Service (missing
log encryption, missing log replication to the bucket
under different AWS account) as well as Security
Groups
www.securing.biz
„Through 2022, at least 95%
of cloud security failures will be the
customer’s fault”
www.securing.biz
Gartner's report, source:
https://www.gartner.com/smarterwithgartner/is-the-cloud-secure/
CloudGoat: https://bit.ly/2TKxczt
CloudGoat walkthrough: https://bit.ly/2u4QYXO
Pacu: https://bit.ly/2SYJKyX
KrkAnalytica CTF: https://bit.ly/2ZFF9Gh
7-Step Guide to SecuRing your
AWS Kingdom: https://bit.ly/2EN7yAs
CloudMapper: https://bit.ly/2NV6zSY
Prowler: https://bit.ly/2kxy879
www.securing.biz
Extras
If so, contact me on:
pawel.rzepa@securing.pl
Do you have any questions?
Could you give me any feedback?

More Related Content

Recently uploaded

Recently uploaded (20)

Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 

Featured

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Saba Software
 
Introduction to C Programming Language
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming Language
Simplilearn
 

Featured (20)

How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them wellGood Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
Good Stuff Happens in 1:1 Meetings: Why you need them and how to do them well
 
Introduction to C Programming Language
Introduction to C Programming LanguageIntroduction to C Programming Language
Introduction to C Programming Language
 

"Attacking AWS: the full cyber kill chain" - Paweł Rzepa