AWS - Accounts Unauthenticated Enum

Reading time: 2 minutes

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks

Vitambulisho vya Akaunti

Ikiwa una lengo, kuna njia za kujaribu kutambua vitambulisho vya akaunti zinazohusiana na lengo.

Brute-Force

Unaunda orodha ya vitambulisho vya akaunti vinavyowezekana na majina ya utani na kuzicheki.

bash
# Check if an account ID exists
curl -v https://<acount_id>.signin.aws.amazon.com
## If response is 404 it doesn't, if 200, it exists
## It also works from account aliases
curl -v https://vodafone-uk2.signin.aws.amazon.com

You can automate this process with this tool.

OSINT

Tafuta URL zinazojumuisha <alias>.signin.aws.amazon.com zenye alias inayohusiana na shirika.

Marketplace

Kama muuzaji ana instances in the marketplace, unaweza kupata owner id (account id) ya AWS account aliyetumia.

Snapshots

  • Public EBS snapshots (EC2 -> Snapshots -> Public Snapshots)
  • RDS public snapshots (RDS -> Snapshots -> All Public Snapshots)
  • Public AMIs (EC2 -> AMIs -> Public images)

Errors

Meseji nyingi za makosa za AWS (hata 'access denied') zitatoa taarifa hiyo.

References

tip

Jifunze na fanya mazoezi ya AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Jifunze na fanya mazoezi ya GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE) Jifunze na fanya mazoezi ya Azure Hacking: HackTricks Training Azure Red Team Expert (AzRTE)

Support HackTricks