daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

5439-pentesting-redshift.md (7516B)


      1 ---
      2 title: "5439 - Pentesting Redshift"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/5439-pentesting-redshift.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/5439-pentesting-redshift.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 5439 - Pentesting Redshift
     14 
     15 ## Basic Information
     16 
     17 This port is used by **Amazon Redshift** (AWS managed data warehouse). Redshift wire protocol is a slightly modified **PostgreSQL** protocol, so most Postgres client tooling works (psql, psycopg2, JDBC/ODBC) but auth and TLS requirements differ.
     18 
     19 For more information check:
     20 
     21 [Aws Redshift Enum.Html](https%3A//cloud.hacktricks.wiki/en/pentesting-cloud/aws-security/aws-services/aws-redshift-enum.html)
     22 
     23 ## Enumeration & Connectivity
     24 
     25 - Default port: **5439/TCP** (customizable). Serverless workgroups also default to 5439.
     26 - Public endpoint pattern: `<clusterid>.<random>.<region>.redshift.amazonaws.com` (public) or `.redshift.amazonaws.com.cn` (China). Serverless: `<workgroup>.<random>.<region>.redshift-serverless.amazonaws.com`.
     27 - **TLS**: Redshift requires TLS 1.2+ and perfect-forward-secrecy ciphers. Old clients may fail; force modern TLS:
     28   ```bash
     29   psql "host=<endpoint> port=5439 user=awsuser dbname=dev sslmode=require"
     30   # or using redshift-psql wrapper
     31   ```
     32 - **Parameter group `require_ssl`** controls if plaintext is allowed. New clusters/workgroups use `default.redshift-2.0` with `require_ssl=true`, so downgrade/mitm is harder.<sup>[[2]](#references)</sup>
     33 
     34 ### Quick enum with psql
     35 
     36 ```bash
     37 # basic banner/version
     38 psql "host=<endpoint> user=<u> dbname=dev" -c 'select version();'
     39 # list dbs, users, privileges
     40 \l
     41 \du
     42 select * from pg_user;
     43 select * from svv_redshift_sessions;
     44 ```
     45 Errors differentiate bad password vs missing user → potential **username enumeration** during brute force.
     46 
     47 ## Authentication paths to test
     48 
     49 - **Database password** for master user (often named `awsuser`) or created DB users.
     50 - **IAM temporary database credentials**: Redshift JDBC/ODBC drivers can use settings such as `authMech=IAM` and provider plug-ins such as `plugin_name=com.amazon.redshift.plugin.OktaCredentialsProvider`; the CLI/API can call `redshift:GetClusterCredentials` (or newer IAM/serverless credential operations). This is distinct from RDS IAM authentication and does **not** use `rds-db:connect`. Test whether compromised IAM principals can call the applicable Redshift credential action and whether `CreateClusterUser`/`JoinGroup` permissions expand the resulting database access.<sup>[[1]](#references)</sup><sup>[[5]](#references)</sup>
     51   ```bash
     52   aws redshift get-cluster-credentials --cluster-identifier <id> \
     53       --db-user pentest --db-name dev --duration-seconds 900
     54   psql "host=<endpoint> user=pentest password=<token> dbname=dev sslmode=require"
     55   ```
     56 - **IAM Identity Center / SAML / Azure AD plugins**: JDBC `plugin_name` may spin up local webserver for SSO; captured loopback callback can leak SAML assertion or temp creds.
     57 
     58 ## Common misconfigurations (network)
     59 
     60 - Cluster marked **PubliclyAccessible=true** with wide-open SG (0.0.0.0/0) exposes Postgres-like surface for brute force or SQLi exploitation.
     61 - **Default port 5439** plus default SG allows easy discovery (Shodan/Censys). Changing port is minor obscurity but sometimes overlooked in hardening checklists.
     62 - **No enhanced VPC routing** → Redshift routes COPY/UNLOAD traffic through the internet, including traffic to other AWS services. An attacker who already has database and IAM permissions may be able to UNLOAD data to an allowed S3 destination; the routing setting does not itself grant bucket access.<sup>[[6]](#references)</sup>
     63 
     64 ## Attack notes
     65 
     66 - If login succeeds, Redshift lacks superuser in serverless; in provisioned clusters the master user has broad rights including creating UDFs (Python), external schema to Spectrum, COPY from attacker S3, and `UNLOAD` to exfil data.
     67 - Check cluster parameter group for `max_concurrency_scaling_clusters`, `require_ssl`, `enable_user_activity_logging` – logging disabled aids stealth.
     68 - Serverless workgroups still reachable via TCP; same SQL attack surface as provisioned clusters.
     69 - **Client-side metadata SQLi (Dec 2024)**: JDBC 2.1.0.31, Python connector 2.1.4 and ODBC 2.1.5.0 build metadata queries with unquoted user input in `getSchemas/getTables/getColumns` (CVE-2024-12744/5/6). If an app lets attackers control catalog or pattern arguments, you can inject arbitrary SQL that runs with the DB user used by the connector.<sup>[[3]](#references)</sup>
     70   ```python
     71   # exploit vulnerable python connector 2.1.4 via metadata API
     72   import redshift_connector
     73   conn = redshift_connector.connect(host='<endpoint>', database='dev', user='lowpriv', password='pw')
     74   cur = conn.cursor()
     75   # injection in table_pattern leaks data from pg_tables
     76   cur.get_tables(table_schema='public', table_name_pattern="%' UNION SELECT usename,passwd FROM pg_user--")
     77   ```
     78 - **UDF execution model change**: Redshift stopped allowing creation of new Python UDFs after October 30, 2025, but existing Python UDFs continue to function. Python UDFs cannot access the network or filesystem, so treat them as database-compute primitives rather than generic host RCE. Lambda UDFs execute in Lambda and inherit that function's IAM role and network reachability; an overprivileged or VPC-connected function may therefore become a pivot to AWS, Internet, or private VPC endpoints, but it does not provide direct access to the Redshift host filesystem.<sup>[[4]](#references)</sup><sup>[[7]](#references)</sup>
     79 
     80 ## Recent security changes (offense impact)
     81 
     82 - **Public access disabled by default** on new clusters/snapshots (Jan 10, 2025 change). Legacy ones may still be public.<sup>[[2]](#references)</sup>
     83 - **Encryption at rest + enforced TLS by default** means sniffing/mitm harder; need valid credentials or SSRF into VPC path.
     84 - **Serverless VPCE rollout change (Jun 27, 2025)**: workgroup endpoints created in up to 3 AZs at creation time. Discovery tools should enumerate all workgroup VPCE DNS names per AZ to find reachable IPs.
     85 
     86 ## References
     87 
     88 - [1] [AWS Docs – Options for providing IAM credentials (JDBC/ODBC IAM/SAML plugins)](https://docs.aws.amazon.com/redshift/latest/mgmt/options-for-providing-iam-credentials.html)
     89 - [2] [AWS Security Blog – Redshift enhances security by changing default behavior (public access off, require SSL, encryption) – 2025](https://aws.amazon.com/blogs/security/amazon-redshift-enhances-security-by-changing-default-behavior-in-2025/)
     90 - [3] [AWS Security Bulletin – SQLi in Redshift JDBC/Python/ODBC drivers (CVE-2024-12744/5/6)](https://aws.amazon.com/security/security-bulletins/AWS-2024-015/)
     91 - [4] [AWS Big Data Blog – Python UDF end-of-support and migration to Lambda UDFs (Jan 2026)](https://aws.amazon.com/blogs/big-data/amazon-redshift-python-user-defined-functions-will-reach-end-of-support-after-june-30-2026/)
     92 - [5] [AWS - Generating temporary database credentials with `GetClusterCredentials`](https://docs.aws.amazon.com/redshift/latest/mgmt/generating-iam-credentials-cli-api.html)
     93 - [6] [AWS - Enhanced VPC routing](https://docs.aws.amazon.com/redshift/latest/mgmt/enhanced-vpc-routing.html)
     94 - [7] [AWS - Python UDF constraints](https://docs.aws.amazon.com/redshift/latest/dg/udf-constraints.html)