AWS S3 Enumeration Basics
| 2024-6-22
字数 461阅读时长 2 分钟
It's your first day on the red team, and you've been tasked with examining a website that was found in a phished employee's bookmarks. Check it out and see where it leads! In scope is the company's infrastructure, including cloud services.
题目提供了一个网站:http://dev.huge-logistics.com
 
F12 查看源码发现用了 aws s3
 
查看内容
 
发现有的目录是没权限的,但这个有,看名字是用来做迁移的,拿下来
 
解压后发现是个 powershell 脚本,里面内容为
泄漏了 aksk,估计脚本是做迁移用的
 
这个 aksk 有 dev.huge-logistics.com 桶的完整权限
 
拿下 flag,但好像并没有权限
 
继续看看其他文件,想了下,刚刚的ps脚本还会从 export.xml 读 secret 的,拉下来瞧瞧 👀,里面有个 AWS IT Admin 的 aksk
 
老套娃了,配置一下,即可拿到 flag
 
进一步阅读
https://blog.gitguardian.com/uber-breach-2022/ - uber 的被手机手段和这个靶场里的还有那么点类似
Loading...
目录