Repository navigation
CloudGoat Official Walkthrough Series ‘sqs_flag_shop’ - #462
Closed
carlospolop wants to merge 1 commit into
Closed
carlospolop wants to merge 1 commit into
carlospolop wants to merge 1 commit into
Conversation
Collaborator
Author
🔗 Additional ContextOriginal Blog Post: https://rhinosecuritylabs.com/research/cloudgoat-walkthrough-sqs_flag_shop Content Categories: Based on the analysis, this content was categorized under "AWS Pentesting -> AWS - Post Exploitation -> AWS - SQS Post Exploitation, with a cross-reference from AWS - Privilege Escalation for IAM enumeration and sts:AssumeRole pivots. A suitable subsection would be SQS Message Injection and Trusted Consumer Abuse.". Repository Maintenance:
Review Notes:
Bot Version: HackTricks News Bot v1.0 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🤖 Automated Content Update
This PR was automatically generated by the HackTricks News Bot based on a technical blog post.
📝 Source Information
🎯 Content Summary
Scope and classification. Rhino Security Labs presents
sqs_flag_shop, a CloudGoat capture-the-flag scenario. CloudGoat is Rhino Security Labs’ “vulnerable by design” cloud-deployment tool for creating intentionally insecure AWS environments; it should be used only in an isolated lab account. The introduction describes the scenario as a privilege-escalation exercise involving AWS Glue, but the detailed walkthrough demonstrates an SQS-based permission pivot and application busi...🔧 Technical Details
IAM enumeration and cloud role pivot: With valid but limited AWS credentials, first call
sts get-caller-identity, then enumerate IAM policies usingiam list-user-policies,iam get-user-policy,iam list-role-policies, andiam get-role-policy. Broadiam:Get*/iam:List*permissions can reveal role names, inline policies, and resource ARNs. If the principal is allowed to callsts:AssumeRoleon a target role and the target trust policy permits the assumption, request temporary credentials withaws sts assume-role, configure the returned access key, secret key, and session token as a new profile, and use the new permissions for the next pivot. This can provide cloud privilege escalation or lateral movement even when the target role is not an administrator role. (rhinosecuritylabs.com)...
🤖 Agent Actions
ERROR: Codex exec failed (exit=1).
{"type":"thread.started","thread_id":"01a116c9-5d86-73a3-9678-3d1948a0ed33"}
{"type":"item.completed","item":{"id":"item_0","type":"error","message":"Model metadata for
gpt-6.1-solnot found. Defaulting to fallback metadata; this can degrade performance and cause issues."}}{"type":"turn.started"}
{"type":"error","message":"{"type":"error","status":400,"error":{"type":"invalid_request_error","message":"The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account."}}"}
{"type":"turn.failed","error":{"message":"{"type":"error","status":400,"error":{"type":"invalid_request_error","message":"The 'gpt-6.1-sol' model is not supported when using Codex with a ChatGPT account."}}"}}
MCP startup status: {"tool_names":["brave_search","check_budget_status","exec","search_google_web"],"error":""}
This PR was automatically created by the HackTricks Feed Bot. Please review the changes carefully before merging.
📚 Repository Maintenance
All .md files have been checked for proper formatting (headers, includes, etc.).