Beanstalk (CloudGoat)
Beanstalk
Initial Access
# credentials
initial_low_priv_credentials = Access Key: AKIA4YM7GTDHDNB4GXV7
Secret Key: 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
# configure
aws configure --profile low_level
AWS Access Key ID [None]: AKIA4YM7GTDHDNB4GXV7
AWS Secret Access Key [None]: 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
Default region name [None]: us-east-1
Default output format [None]: json
#whoami
aws sts get-caller-identity --profile low_level
{
"UserId": "AIDA4YM7GTDHOLCJS5VMB",
"Account": "877044078798",
"Arn": "arn:aws:iam::877044078798:user/cgidg0l919nvpe_low_priv_user"
}
Enumeration
Enumerating Beanstalk applications and environments
Enumerating as the secondary user
Enumerating users within the AWS account
Listing attached user policies for secondary user
Viewing attached user policy metadata
Viewing the actual attached policy
Privilege esc to Admin User
Last updated