├── .gitignore ├── README.md ├── elevation ├── add_iam_policy.py ├── assume_roles.py ├── bouncy_bouncy_cloudy_cloud.py ├── dump_cloudformation_stack_descriptions.py ├── dump_instance_attributes.py └── send_meta_data_credentials.sh ├── exploration └── dump_account_data.sh ├── miscellanea ├── Kiwicon 2016 - Hacking AWS End to End.pdf ├── download_docs.sh ├── endpoints.txt ├── integrations.txt ├── principals.txt └── reserved_words.txt ├── persistence ├── backdoor_all_roles.py ├── backdoor_all_security_groups.py ├── backdoor_all_users.py ├── backdoor_created_roles_lambda │ └── backdoor_created_roles_lambda.py ├── backdoor_created_security_groups_lambda │ └── backdoor_created_security_groups_lambda.py ├── backdoor_created_users_lambda │ └── backdoor_created_users_lambda.py ├── cli_lambda │ └── cli_lambda.py └── rabbit_lambda │ └── rabbit_lambda.py ├── reconnaissance ├── validate_accounts.py ├── validate_iam_access_keys.py ├── validate_iam_principals.py └── validate_s3_buckets.py ├── requirements.txt └── stealth └── disrupt_cloudtrail.py /.gitignore: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/.gitignore -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/README.md -------------------------------------------------------------------------------- /elevation/add_iam_policy.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/add_iam_policy.py -------------------------------------------------------------------------------- /elevation/assume_roles.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/assume_roles.py -------------------------------------------------------------------------------- /elevation/bouncy_bouncy_cloudy_cloud.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/bouncy_bouncy_cloudy_cloud.py -------------------------------------------------------------------------------- /elevation/dump_cloudformation_stack_descriptions.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/dump_cloudformation_stack_descriptions.py -------------------------------------------------------------------------------- /elevation/dump_instance_attributes.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/dump_instance_attributes.py -------------------------------------------------------------------------------- /elevation/send_meta_data_credentials.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/elevation/send_meta_data_credentials.sh -------------------------------------------------------------------------------- /exploration/dump_account_data.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/exploration/dump_account_data.sh -------------------------------------------------------------------------------- /miscellanea/Kiwicon 2016 - Hacking AWS End to End.pdf: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/Kiwicon 2016 - Hacking AWS End to End.pdf -------------------------------------------------------------------------------- /miscellanea/download_docs.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/download_docs.sh -------------------------------------------------------------------------------- /miscellanea/endpoints.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/endpoints.txt -------------------------------------------------------------------------------- /miscellanea/integrations.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/integrations.txt -------------------------------------------------------------------------------- /miscellanea/principals.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/principals.txt -------------------------------------------------------------------------------- /miscellanea/reserved_words.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/miscellanea/reserved_words.txt -------------------------------------------------------------------------------- /persistence/backdoor_all_roles.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_all_roles.py -------------------------------------------------------------------------------- /persistence/backdoor_all_security_groups.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_all_security_groups.py -------------------------------------------------------------------------------- /persistence/backdoor_all_users.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_all_users.py -------------------------------------------------------------------------------- /persistence/backdoor_created_roles_lambda/backdoor_created_roles_lambda.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_created_roles_lambda/backdoor_created_roles_lambda.py -------------------------------------------------------------------------------- /persistence/backdoor_created_security_groups_lambda/backdoor_created_security_groups_lambda.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_created_security_groups_lambda/backdoor_created_security_groups_lambda.py -------------------------------------------------------------------------------- /persistence/backdoor_created_users_lambda/backdoor_created_users_lambda.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/backdoor_created_users_lambda/backdoor_created_users_lambda.py -------------------------------------------------------------------------------- /persistence/cli_lambda/cli_lambda.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/cli_lambda/cli_lambda.py -------------------------------------------------------------------------------- /persistence/rabbit_lambda/rabbit_lambda.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/persistence/rabbit_lambda/rabbit_lambda.py -------------------------------------------------------------------------------- /reconnaissance/validate_accounts.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/reconnaissance/validate_accounts.py -------------------------------------------------------------------------------- /reconnaissance/validate_iam_access_keys.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/reconnaissance/validate_iam_access_keys.py -------------------------------------------------------------------------------- /reconnaissance/validate_iam_principals.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/reconnaissance/validate_iam_principals.py -------------------------------------------------------------------------------- /reconnaissance/validate_s3_buckets.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/reconnaissance/validate_s3_buckets.py -------------------------------------------------------------------------------- /requirements.txt: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/requirements.txt -------------------------------------------------------------------------------- /stealth/disrupt_cloudtrail.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/dagrz/aws_pwn/HEAD/stealth/disrupt_cloudtrail.py --------------------------------------------------------------------------------