daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-cognito.md (3246B)


      1 ---
      2 title: "AWS - Service - Cognito"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-cognito.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-cognito.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Service - Cognito
     12 
     13 AWS Cognito is an AWS-managed service for authentication, authorization, and user management.
     14 
     15 1. A user signs in through Cognito User Pools (authentication) or via a federated IdP (Google, Facebook, SAML, etc.).
     16 2. Cognito Identity Pools can then exchange this identity for temporary AWS credentials (from STS — Security Token Service).
     17 3. These credentials (Access Key ID, Secret Access Key, and Session Token) let the app directly call AWS services (e.g., S3, DynamoDB, API Gateway) with limited IAM roles/policies.
     18 
     19 ## Tools
     20 
     21 * [Cognito Scanner](https://github.com/padok-team/cognito-scanner) - A CLI tool for executing attacks on cognito such as *Unwanted account creation*, *Account Oracle* and *Identity Pool escalation*.
     22 
     23     ```ps1
     24     # Installation
     25     $ pip install cognito-scanner
     26     # Usage
     27     $ cognito-scanner --help
     28     # Get information about how to use the unwanted account creation script
     29     $ cognito-scanner account-creation --help
     30     # For more details go to https://github.com/padok-team/cognito-scanner
     31     ```
     32 
     33 ## Identity Pool ID
     34 
     35 * **User Pools** : User pools allow sign-in and sign-up functionality
     36 * **Identity Pools** : Identity pools allow authenticated and unauthenticated users to access AWS resources using temporary credentials
     37 
     38 Once you have the Cognito Identity Pool Id token, you can proceed further and fetch Temporary AWS Credentials for an unauthenticated role using the identified tokens.
     39 
     40 ```py
     41 import boto3
     42 
     43 region='us-east-1'
     44 identity_pool='us-east-1:5280c436-2198-2b5a-b87c-9f54094x8at9'
     45 
     46 client = boto3.client('cognito-identity',region_name=region)
     47 _id = client.get_id(IdentityPoolId=identity_pool)
     48 _id = _id['IdentityId']
     49 
     50 credentials = client.get_credentials_for_identity(IdentityId=_id)
     51 access_key = credentials['Credentials']['AccessKeyId']
     52 secret_key = credentials['Credentials']['SecretKey']
     53 session_token = credentials['Credentials']['SessionToken']
     54 identity_id = credentials['IdentityId']
     55 print("Access Key: " + access_key)
     56 print("Secret Key: " + secret_key)
     57 print("Session Token: " + session_token)
     58 print("Identity Id: " + identity_id)
     59 ```
     60 
     61 ## AWS Cognito Commands
     62 
     63 ### Get User Information
     64 
     65 ```ps1
     66 aws cognito-idp get-user --access-token $(cat access_token.txt)
     67 ```
     68 
     69 ### Admin Authentication
     70 
     71 ```ps1
     72 aws cognito-idp admin-initiate-auth --access-token $(cat access_token)
     73 ```
     74 
     75 ### List User Groups
     76 
     77 ```ps1
     78 aws cognito-idp admin-list-groups-for-user --username user.name@email.com --user-pool-id "Group-Name"
     79 ```
     80 
     81 ### Sign up
     82 
     83 ```ps1
     84 aws cognito-idp sign-up --client-id <client-id> --username <username> --password <password>
     85 ```
     86 
     87 ### Modify Attributes
     88 
     89 ```ps1
     90 aws cognito-idp update-user-attributes --access-token $(cat access_token) --user-attributes Name=<attribute>,Value=<value>
     91 ```
     92 
     93 ## References
     94 
     95 * [Exploiting weak configurations in Amazon Cognito - Pankaj Mouriya - April 6, 2021](https://blog.appsecco.com/exploiting-weak-configurations-in-amazon-cognito-in-aws-471ce761963)