AWS - DocumentDB Enum

Reading time: 3 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

DocumentDB

Amazon DocumentDB, inayotoa ulinganifu na MongoDB, inawasilishwa kama huduma ya hifadhidata ya haraka, ya kuaminika, na inayosimamiwa kikamilifu. Imeundwa kwa urahisi katika usakinishaji, uendeshaji, na upanuzi, inaruhusu uhamishaji na uendeshaji usio na mshono wa hifadhidata zinazolingana na MongoDB katika wingu. Watumiaji wanaweza kutumia huduma hii kutekeleza msimbo wao wa programu uliopo na kutumia madereva na zana zinazofahamika, kuhakikisha mpito na uendeshaji laini kama kufanya kazi na MongoDB.

Enumeration

bash
aws docdb describe-db-clusters # Get username from "MasterUsername", get also the endpoint from "Endpoint"
aws docdb describe-db-instances #Get hostnames from here

# Parameter groups
aws docdb describe-db-cluster-parameter-groups
aws docdb describe-db-cluster-parameters --db-cluster-parameter-group-name <param_group_name>

# Snapshots
aws docdb describe-db-cluster-snapshots
aws --region us-east-1 --profile ad docdb describe-db-cluster-snapshot-attributes --db-cluster-snapshot-identifier <snap_id>

NoSQL Injection

Kwa kuwa DocumentDB ni hifadhidata inayofanana na MongoDB, unaweza kufikiria kwamba pia ina udhaifu kwa mashambulizi ya kawaida ya NoSQL injection:

NoSQL injection - HackTricks

DocumentDB

AWS - DocumentDB Unauthenticated Enum

References

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks