It's your first day on the red team, and you've been tasked with examining a website that was found in a phished employee's bookmarks. Check it out and see where it leads! In scope is the company's infrastructure, including cloud services.
题目提供了一个网站:http://dev.huge-logistics.com
F12 查看源码发现用了 aws s3
查看内容
发现有的目录是没权限的,但这个有,看名字是用来做迁移的,拿下来
解压后发现是个 powershell 脚本,里面内容为
泄漏了 aksk,估计脚本是做迁移用的
这个 aksk 有 dev.huge-logistics.com 桶的完整权限
拿下 flag,但好像并没有权限
继续看看其他文件,想了下,刚刚的ps脚本还会从 export.xml 读 secret 的,拉下来瞧瞧 👀,里面有个 AWS IT Admin 的 aksk
老套娃了,配置一下,即可拿到 flag
进一步阅读
https://blog.gitguardian.com/uber-breach-2022/ - uber 的被手机手段和这个靶场里的还有那么点类似
