AWS - Directory Services Privesc

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

Directory Services

Kwa maelezo zaidi kuhusu Directory Services angalia:

AWS - Directory Services / WorkDocs Enum

ds:ResetUserPassword

Ruhusa hii inaruhusu kubadilisha nenosiri la mtumiaji yoyote aliyewepo katika Active Directory.
Kwa chaguo-msingi, mtumiaji pekee aliyewepo ni Admin.

aws ds reset-user-password --directory-id <id> --user-name Admin --new-password Newpassword123.

AWS Management Console

Inawezekana kuwezesha application access URL ambayo watumiaji kutoka AD wanaweza kuitumia kuingia:

Kisha watapewa AWS IAM role wanapoingia, kwa hivyo mtumiaji au kikundi wa AD atakuwa na ufikiaji wa AWS Management Console:

Inaonekana hakuna njia ya kuwezesha application access URL, AWS Management Console na kutoa ruhusa

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks