AWS - DocumentDB Enum
Reading time: 3 minutes
tip
Jifunze na fanya mazoezi ya AWS Hacking:
HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking:
HackTricks Training GCP Red Team Expert (GRTE)
Jifunze na fanya mazoezi ya Azure Hacking:
HackTricks Training Azure Red Team Expert (AzRTE)
Support HackTricks
- Angalia mpango wa usajili!
- Jiunge na 💬 kikundi cha Discord au kikundi cha telegram au tufuatilie kwenye Twitter 🐦 @hacktricks_live.
- Shiriki mbinu za hacking kwa kuwasilisha PRs kwa HackTricks na HackTricks Cloud repos za github.
DocumentDB
Amazon DocumentDB, inayotoa ulinganifu na MongoDB, inatambulika kama huduma ya hifadhidata ya haraka, ya kuaminika, na iliyosimamiwa kikamilifu. Iliyoundwa kwa urahisi katika utoaji, uendeshaji, na upanukaji, inaruhusu uhamisho na uendeshaji usio na mshono wa hifadhidata zinazolingana na MongoDB kwenye mawingu. Watumiaji wanaweza kutumia huduma hii kuendesha msimbo wa programu wao uliopo na kutumia madereva na zana zinazowafahamisha, hivyo kuhakikisha mabadiliko laini na uendeshaji unaofanana na kufanya kazi na MongoDB.
Enumeration
aws docdb describe-db-clusters # Get username from "MasterUsername", get also the endpoint from "Endpoint"
aws docdb describe-db-instances #Get hostnames from here
# Parameter groups
aws docdb describe-db-cluster-parameter-groups
aws docdb describe-db-cluster-parameters --db-cluster-parameter-group-name <param_group_name>
# Snapshots
aws docdb describe-db-cluster-snapshots
aws --region us-east-1 --profile ad docdb describe-db-cluster-snapshot-attributes --db-cluster-snapshot-identifier <snap_id>
NoSQL Injection
Kwa kuwa DocumentDB ni database inayolingana na MongoDB, unaweza kufikiria pia iko hatarini kwa mashambulizi ya kawaida ya NoSQL injection:
DocumentDB
AWS - DocumentDB Unauthenticated Enum
Marejeo
- https://aws.amazon.com/blogs/database/analyze-amazon-documentdb-workloads-with-performance-insights/
tip
Jifunze na fanya mazoezi ya AWS Hacking:
HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking:
HackTricks Training GCP Red Team Expert (GRTE)
Jifunze na fanya mazoezi ya Azure Hacking:
HackTricks Training Azure Red Team Expert (AzRTE)
Support HackTricks
- Angalia mpango wa usajili!
- Jiunge na 💬 kikundi cha Discord au kikundi cha telegram au tufuatilie kwenye Twitter 🐦 @hacktricks_live.
- Shiriki mbinu za hacking kwa kuwasilisha PRs kwa HackTricks na HackTricks Cloud repos za github.
HackTricks Cloud