AWS - DocumentDB Enum

Reading time: 3 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

DocumentDB

Amazon DocumentDB, inayotoa ulinganifu na MongoDB, inatambulika kama huduma ya hifadhidata ya haraka, ya kuaminika, na iliyosimamiwa kikamilifu. Iliyoundwa kwa urahisi katika utoaji, uendeshaji, na upanukaji, inaruhusu uhamisho na uendeshaji usio na mshono wa hifadhidata zinazolingana na MongoDB kwenye mawingu. Watumiaji wanaweza kutumia huduma hii kuendesha msimbo wa programu wao uliopo na kutumia madereva na zana zinazowafahamisha, hivyo kuhakikisha mabadiliko laini na uendeshaji unaofanana na kufanya kazi na MongoDB.

Enumeration

bash
aws docdb describe-db-clusters # Get username from "MasterUsername", get also the endpoint from "Endpoint"
aws docdb describe-db-instances #Get hostnames from here

# Parameter groups
aws docdb describe-db-cluster-parameter-groups
aws docdb describe-db-cluster-parameters --db-cluster-parameter-group-name <param_group_name>

# Snapshots
aws docdb describe-db-cluster-snapshots
aws --region us-east-1 --profile ad docdb describe-db-cluster-snapshot-attributes --db-cluster-snapshot-identifier <snap_id>

NoSQL Injection

Kwa kuwa DocumentDB ni database inayolingana na MongoDB, unaweza kufikiria pia iko hatarini kwa mashambulizi ya kawaida ya NoSQL injection:

NoSQL injection - HackTricks

DocumentDB

AWS - DocumentDB Unauthenticated Enum

Marejeo

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks