diff --git a/src/pentesting-cloud/aws-security/aws-persistence/aws-elasticache-persistence/README.md b/src/pentesting-cloud/aws-security/aws-persistence/aws-elasticache-persistence/README.md index d776833b99..9d7a488db6 100644 --- a/src/pentesting-cloud/aws-security/aws-persistence/aws-elasticache-persistence/README.md +++ b/src/pentesting-cloud/aws-security/aws-persistence/aws-elasticache-persistence/README.md @@ -41,7 +41,7 @@ aws elasticache modify-user --user-id default \ -{{#include ../../../../banners/hacktricks-training.md}} + ### `elasticache:CreateUser`, `elasticache:CreateUserGroup` | `elasticache:ModifyUserGroup` — plant a full-access RBAC user @@ -102,3 +102,4 @@ For an **existing** group, `ModifyUserGroup` evaluates more than the group ARN. - [2] [Resource-level permissions - Amazon ElastiCache](https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/IAM.ResourceLevelPermissions.html) - [3] [Logging ElastiCache API calls with AWS CloudTrail - Amazon ElastiCache](https://docs.aws.amazon.com/AmazonElastiCache/latest/dg/logging-using-cloudtrail.html) - [4] [CreateUserGroup - Amazon ElastiCache API](https://docs.aws.amazon.com/AmazonElastiCache/latest/APIReference/API_CreateUserGroup.html) +{{#include ../../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/aws-security/aws-persistence/aws-refactor-spaces-persistence/README.md b/src/pentesting-cloud/aws-security/aws-persistence/aws-refactor-spaces-persistence/README.md index 64327b7279..33d48fc95e 100644 --- a/src/pentesting-cloud/aws-security/aws-persistence/aws-refactor-spaces-persistence/README.md +++ b/src/pentesting-cloud/aws-security/aws-persistence/aws-refactor-spaces-persistence/README.md @@ -71,3 +71,4 @@ Version 2 allowed read access plus `CreateApplication`, `CreateService`, and `Cr - [Shareable AWS resources](https://docs.aws.amazon.com/ram/latest/userguide/shareable.html) - [PutResourcePolicy API](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/APIReference/API_PutResourcePolicy.html) - [How Refactor Spaces works](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/how-it-works.html) +{{#include ../../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/aws-security/aws-services/aws-payment-cryptography-enum.md b/src/pentesting-cloud/aws-security/aws-services/aws-payment-cryptography-enum.md index 62f51eea2e..6103decbbf 100644 --- a/src/pentesting-cloud/aws-security/aws-services/aws-payment-cryptography-enum.md +++ b/src/pentesting-cloud/aws-security/aws-services/aws-payment-cryptography-enum.md @@ -1,6 +1,7 @@ # AWS - Payment Cryptography Enum {{#include ../../../banners/hacktricks-training.md}} + ## Payment Cryptography AWS Payment Cryptography is a managed hardware-security-module service for payment keys and payment-specific cryptographic operations. It has two API surfaces: diff --git a/src/pentesting-cloud/aws-security/aws-services/aws-refactor-spaces-enum.md b/src/pentesting-cloud/aws-security/aws-services/aws-refactor-spaces-enum.md index 020e95ea23..2cbfa0c6c3 100644 --- a/src/pentesting-cloud/aws-security/aws-services/aws-refactor-spaces-enum.md +++ b/src/pentesting-cloud/aws-security/aws-services/aws-refactor-spaces-enum.md @@ -191,3 +191,4 @@ Refactor Spaces API calls are CloudTrail management events with `eventSource=ref - [Sharing environments using AWS RAM](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/sharing.html) - [Actions, resources, and condition keys](https://docs.aws.amazon.com/service-authorization/latest/reference/list_migration-hub-refactor-spaces.html) - [Logging Refactor Spaces API calls with CloudTrail](https://docs.aws.amazon.com/migrationhub-refactor-spaces/latest/userguide/logging-using-cloudtrail.html) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/aws-security/aws-services/aws-signin-enum.md b/src/pentesting-cloud/aws-security/aws-services/aws-signin-enum.md index 0c08c9f5e2..cff27d614e 100644 --- a/src/pentesting-cloud/aws-security/aws-services/aws-signin-enum.md +++ b/src/pentesting-cloud/aws-security/aws-services/aws-signin-enum.md @@ -26,3 +26,4 @@ A `ResourceNotFoundException` can mean no configuration or policy exists. Inspec 1. [AWS Sign-In console access control](https://docs.aws.amazon.com/signin/latest/userguide/console-access-control.html) 2. [AWS Sign-In actions and permissions](https://docs.aws.amazon.com/service-authorization/latest/reference/list_signin.html) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/aws-security/aws-services/aws-supply-chain-enum.md b/src/pentesting-cloud/aws-security/aws-services/aws-supply-chain-enum.md index bf47086935..8e8e69fa92 100644 --- a/src/pentesting-cloud/aws-security/aws-services/aws-supply-chain-enum.md +++ b/src/pentesting-cloud/aws-security/aws-services/aws-supply-chain-enum.md @@ -1,6 +1,7 @@ # AWS - Supply Chain Enum {{#include ../../../banners/hacktricks-training.md}} + ## AWS Supply Chain AWS Supply Chain (`scn`) provides a regional, Identity Center-backed web application and a SigV4 API for instances, data-lake schemas, ingestion events, SQL transformation flows and bill-of-materials imports. An instance can contain commercially sensitive inventory, forecasts, orders, shipments, supplier and manufacturing data. diff --git a/src/pentesting-cloud/aws-security/permission-risk-categorizations.md b/src/pentesting-cloud/aws-security/permission-risk-categorizations.md index 653d4a3d2c..0cbad28304 100644 --- a/src/pentesting-cloud/aws-security/permission-risk-categorizations.md +++ b/src/pentesting-cloud/aws-security/permission-risk-categorizations.md @@ -1,5 +1,7 @@ # AWS permissions categories +{{#include ../../banners/hacktricks-training.md}} + The canonical [AWS categorization file](../../permission-categorizations/aws.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS. - **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution. @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c +{{#include ../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-ai-search-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-ai-search-privesc.md index 49ab2ff313..c76723adbb 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-ai-search-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-ai-search-privesc.md @@ -238,7 +238,7 @@ Submit the narrow data-plane request directly. A successful configuration PUT ch See [Azure AI Search indexers](https://learn.microsoft.com/en-us/azure/search/search-indexer-overview), [connect to Azure Storage with a managed identity](https://learn.microsoft.com/en-us/azure/search/search-how-to-managed-identities), and the [Search Service REST API](https://learn.microsoft.com/en-us/rest/api/searchservice/). -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -252,3 +252,4 @@ See [Azure AI Search indexers](https://learn.microsoft.com/en-us/azure/search/se - The follow-up blind PUT is a data-plane call to `*.search.windows.net` not captured in the Activity Log (only AI Search OperationLogs, off by default); a 403 on a GET does not imply the corresponding blind write is logged or blocked
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-deployment-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-deployment-privesc.md index d37e6576b5..1cbcb0e6c3 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-deployment-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-deployment-privesc.md @@ -243,7 +243,7 @@ $base = "/subscriptions/$subscriptionId/resourceGroups/$resourceGroup/providers/ Refreshing the Azure CLI or PowerShell token may be necessary immediately after a new exact role assignment. Resource responses redact secure environment variables, but plain values, declared outputs, and printed logs must all be reviewed independently. -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -257,3 +257,4 @@ Refreshing the Azure CLI or PowerShell token may be necessary immediately after - NOT recorded: the specific outputs/log content read is never captured centrally; responses redact secure environment variables but plain values, declared outputs, and printed logs are returned to the caller unlogged.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-template-spec-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-template-spec-privesc.md index 5d850bf186..75f6236c6f 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-template-spec-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-arm-template-spec-privesc.md @@ -58,7 +58,7 @@ Use `Owner` (`8e3af657-a8ff-443c-a75c-2fe8c4bcb635`) instead of `Reader` to take See [Template specs](https://learn.microsoft.com/en-us/azure/azure-resource-manager/templates/template-specs) and [Assign Azure roles using ARM templates](https://learn.microsoft.com/en-us/azure/role-based-access-control/role-assignments-template). -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -73,3 +73,4 @@ See [Template specs](https://learn.microsoft.com/en-us/azure/azure-resource-mana - NOT recorded as the attacker's action: the later victim deployment that executes the payload is logged as the VICTIM's own `Microsoft.Resources/deployments/write` plus the created resources/role assignments under the deployer's identity — not attributed to the attacker; the poisoned template body stored in the version is not shown in the Activity Log, and reads of the version's template are GETs that are not logged.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-communication-services-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-communication-services-privesc.md index 7461c3509f..994a40194d 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-communication-services-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-communication-services-privesc.md @@ -184,10 +184,11 @@ AzurePEASS marks these permissions high. The key grants trusted-service capabili -{{#include ../../../banners/hacktricks-training.md}} + ## References - [1] [Azure Communication Services — Email domains and sender authentication](https://learn.microsoft.com/en-us/azure/communication-services/concepts/email/email-domain-and-sender-authentication) - [Azure Communication Services Chat logs](https://learn.microsoft.com/en-us/azure/communication-services/concepts/analytics/logs/chat-logs) - [Communication Services Azure Monitor tables](https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/microsoft-communication-communicationservices) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-databricks-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-databricks-privesc.md index 838962a44e..c7d2a25fed 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-databricks-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-databricks-privesc.md @@ -182,7 +182,7 @@ Databricks protects the workspace's **managed resource group** (DBFS-root storag See [Databricks cluster init scripts](https://learn.microsoft.com/en-us/azure/databricks/init-scripts/), [global init scripts](https://learn.microsoft.com/en-us/azure/databricks/init-scripts/global), [secret scopes](https://learn.microsoft.com/en-us/azure/databricks/security/secrets/), [Unity Catalog storage credentials](https://learn.microsoft.com/en-us/azure/databricks/connect/unity-catalog/), and [Access Connector for Azure Databricks](https://learn.microsoft.com/en-us/azure/databricks/connect/unity-catalog/storage-credentials). -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -209,3 +209,4 @@ See [Databricks cluster init scripts](https://learn.microsoft.com/en-us/azure/da - The SCIM `admins`-group bootstrap and confirmation calls go to the workspace endpoint `adb-..azuredatabricks.net` — a data-plane operation NOT in the Azure Activity Log; only Databricks' own workspace audit logs (separate product, off/diagnostic-configured) would record it
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-event-grid-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-event-grid-privesc.md index 85ed33c889..547a53fd15 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-event-grid-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-event-grid-privesc.md @@ -426,7 +426,7 @@ The exact property names and their nesting vary between namespaces, topics, and > [!NOTE] > **Cross-tenant partner event injection (`partnerConfigurations/authorizePartner/action`, `partnerConfigurations/write`, `partnerNamespaces/*` — preview/niche).** Partner configuration governs which external partners may push events into the tenant. Authorizing an attacker-controlled partner registration/namespace establishes a sanctioned cross-tenant channel to inject events into partner topics that feed victim subscriptions — a stealthy, tenant-blessed injection/persistence path that resembles a legitimate partner integration. Requires **EventGrid Contributor**; both ops are control-plane and land in the Activity Log (~90d). Authorization expiry can limit how long a partner remains authorized. -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -439,3 +439,4 @@ The exact property names and their nesting vary between namespaces, topics, and - It appears only in the topic's data-plane diagnostic logs (off by default); the separate namespace/topic/subscription management reads are not required, so no `Administrative` entry records the pull.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-fluid-relay-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-fluid-relay-privesc.md index d4a7e9e25e..73756a18ea 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-fluid-relay-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-fluid-relay-privesc.md @@ -86,7 +86,7 @@ References: [Fluid Relay authentication and authorization](https://learn.microso -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -100,3 +100,4 @@ References: [Fluid Relay authentication and authorization](https://learn.microso - The subsequent JWT-signed client access to the Fluid service endpoint is **data-plane** and is **not** in the Activity Log.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-iot-hub-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-iot-hub-privesc.md index a573fb4aad..c9bd5077d6 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-iot-hub-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-iot-hub-privesc.md @@ -473,7 +473,7 @@ See [X.509 CA certificate security with IoT Hub](https://learn.microsoft.com/en- > [!NOTE] > **Defense evasion.** `Microsoft.Devices/iotHubs/diagnosticSettings/write` (and `provisioningServices/diagnosticSettings/write`) let an attacker delete or rewire the diagnostic setting that, in a mature target, routes the IoT Hub/DPS data-plane categories (`DeviceIdentityOperations`, `Connections`, `C2DCommands`, `DirectMethods`, `FileUploadOperations`, `Routes`, DPS `DeviceOperations`/`ServiceOperations`) to Log Analytics/Storage/Event Hub — blinding exactly the telemetry that would record every data-plane technique on this page. The change is itself a control-plane Activity Log — Administrative event (~90d), so disabling logging does not erase the record that logging was changed. `iotHubs/Delete` / `provisioningServices/Delete` are destructive DoS only. -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -487,3 +487,4 @@ See [X.509 CA certificate security with IoT Hub](https://learn.microsoft.com/en- - The DPS `enrollments/read` and `enrollmentGroups/read` actions are DPS data-plane reads over `*.azure-devices-provisioning.net` and are NOT in the Activity Log — only in DPS diagnostic logs (off by default); NOT recorded either way: no key material is returned so nothing sensitive is disclosed.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-notification-hubs-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-notification-hubs-privesc.md index e71efdb324..ad8dfcce05 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-notification-hubs-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-notification-hubs-privesc.md @@ -148,7 +148,7 @@ For persistence techniques, see [Az - Notification Hubs Persistence](../az-persi - [1] [Notification Hubs - Debug Send (REST API)](https://learn.microsoft.com/en-us/rest/api/notificationhubs/notification-hubs/debug-send) -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -161,3 +161,4 @@ For persistence techniques, see [Az - Notification Hubs Persistence](../az-persi - `.../pnsCredentials/action` is logged in the **Activity Log** (Administrative, ~90 days); the returned credential values are only in the response body, not the log.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-quantum-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-quantum-privesc.md index 270f0acc1a..9b41a5bc02 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-quantum-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-quantum-privesc.md @@ -42,7 +42,7 @@ The jobs response can disclose creator information, targets, status, metadata, c If resource enumeration is denied, recover the workspace name, region, resource group, and subscription from a returned connection string, application configuration, source, deployment output, or logs. See [authenticate with Azure Quantum access keys](https://learn.microsoft.com/en-us/azure/quantum/security-manage-access-keys), [list workspace keys](https://learn.microsoft.com/en-us/rest/api/azurequantum/resourcemanager/workspaces/list-keys?view=rest-azurequantum-resourcemanager-2025-12-15-preview), [regenerate workspace keys](https://learn.microsoft.com/en-us/rest/api/azurequantum/resourcemanager/workspaces/regenerate-keys?view=rest-azurequantum-resourcemanager-2025-12-15-preview), and [list jobs](https://learn.microsoft.com/en-us/rest/api/azurequantum/dataplane/jobs/list?view=rest-azurequantum-dataplane-2026-01-15-preview). -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -57,3 +57,4 @@ If resource enumeration is denied, recover the workspace name, region, resource - NOT recorded there: the subsequent `x-ms-quantum-api-key`-authenticated data-plane calls to `..quantum.azure.com` (jobs list, etc.) are not in the Activity Log; they appear only in the Quantum workspace's diagnostic logs, off by default.
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-stream-analytics-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-stream-analytics-privesc.md index 08c9cfef78..dc25d772a7 100644 --- a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-stream-analytics-privesc.md +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-stream-analytics-privesc.md @@ -251,7 +251,7 @@ It operates on supplied credentials (no job → no job MI at location scope), so > [!NOTE] > Stream Analytics has **no** `listKeys`/`listSecrets`/secret-read operation — `inputs/Read`/`outputs/Read` mask the account/shared-access key, so there is no service-native connection-secret-extraction technique. Every op is control-plane (no `isDataAction:true` action exists), so all of the above land in the Activity Log Administrative category by default. `streamingjobs/Scale/action` (inflate streaming units = cost DoS) and the various `Delete` ops are availability/DoS only. Diagnostic-setting teardown is done via `Microsoft.Insights/diagnosticSettings/*` (a different provider), not a Stream-Analytics-specific op. -{{#include ../../../banners/hacktricks-training.md}} +
Logs generated @@ -265,3 +265,4 @@ It operates on supplied credentials (no job → no job MI at location scope), so - The exfiltrated event records written to the attacker's Storage sink are NOT captured by the Stream Analytics job's Azure Activity Log; the data flow itself appears only in the job's/destination's data-plane diagnostic logs (off by default)
+{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/azure-security/permission-risk-categorizations.md b/src/pentesting-cloud/azure-security/permission-risk-categorizations.md index 3789e97305..031d9afc2d 100644 --- a/src/pentesting-cloud/azure-security/permission-risk-categorizations.md +++ b/src/pentesting-cloud/azure-security/permission-risk-categorizations.md @@ -1,5 +1,7 @@ # Azure permissions categories +{{#include ../../banners/hacktricks-training.md}} + The canonical [Azure categorization file](../../permission-categorizations/azure.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS. - **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution. @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c +{{#include ../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-persistence/gcp-healthcare-persistence.md b/src/pentesting-cloud/gcp-security/gcp-persistence/gcp-healthcare-persistence.md index 6595e4ee2e..14900d6685 100644 --- a/src/pentesting-cloud/gcp-security/gcp-persistence/gcp-healthcare-persistence.md +++ b/src/pentesting-cloud/gcp-security/gcp-persistence/gcp-healthcare-persistence.md @@ -190,3 +190,4 @@ The destination owner must attach a subscription before messages can be retained 5. [View Cloud Healthcare API error logs](https://docs.cloud.google.com/healthcare-api/docs/how-tos/logging) 6. [FHIR Pub/Sub notifications](https://docs.cloud.google.com/healthcare-api/docs/fhir-pubsub) 7. [Pub/Sub audit logging](https://docs.cloud.google.com/pubsub/docs/audit-logging) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloud-deploy-privesc.md b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloud-deploy-privesc.md index e8e15982d1..fca549dd36 100644 --- a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloud-deploy-privesc.md +++ b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloud-deploy-privesc.md @@ -220,3 +220,4 @@ The explicit `--condition=None` makes this an unconditional binding even when th 18. [Cloud Deploy CustomTargetType PATCH API](https://docs.cloud.google.com/deploy/docs/api/reference/rest/v1/projects.locations.customTargetTypes/patch) 19. [Cloud Run deployment permissions](https://docs.cloud.google.com/run/docs/reference/iam/roles#deployment_permissions) 20. [IAM Policy version and etag contract](https://docs.cloud.google.com/iam/docs/reference/rest/v1/Policy) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-composer-privesc.md b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-composer-privesc.md index 64dab23062..968fa9e9e3 100644 --- a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-composer-privesc.md +++ b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-composer-privesc.md @@ -265,3 +265,4 @@ gcp-storage-privesc.md 17. [Cloud Storage audit logging](https://docs.cloud.google.com/storage/docs/audit-logging) 18. [Cloud Build audit logging](https://docs.cloud.google.com/build/docs/securing-builds/audit-logs) 19. [Artifact Registry audit logging](https://docs.cloud.google.com/artifact-registry/docs/audit-logging) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-deploymentmaneger-privesc.md b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-deploymentmaneger-privesc.md index 877291d4ee..441e6cc4b8 100644 --- a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-deploymentmaneger-privesc.md +++ b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-deploymentmaneger-privesc.md @@ -50,7 +50,7 @@ resources: serviceAccounts: - email: TARGET_PRIVILEGED_SA@PROJECT_ID.iam.gserviceaccount.com scopes: - - https://www.googleapis.com/auth/cloud-platform + - [https://www.googleapis.com/auth/cloud-platform](https://www.googleapis.com/auth/cloud-platform) metadata: items: - key: startup-script diff --git a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-healthcare-privesc.md b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-healthcare-privesc.md index f9408308ef..889535cb37 100644 --- a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-healthcare-privesc.md +++ b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-healthcare-privesc.md @@ -105,3 +105,4 @@ Cloud Healthcare's audit catalog records the generic IAM method names rather tha 1. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access) 2. [Cloud Healthcare API access control and predefined roles](https://docs.cloud.google.com/healthcare-api/docs/access-control) 3. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-networksecurity-privesc.md b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-networksecurity-privesc.md index 1fc50fd0cc..a93dba2a4d 100644 --- a/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-networksecurity-privesc.md +++ b/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-networksecurity-privesc.md @@ -31,7 +31,7 @@ name: attacker-allow target: loadBalancingScheme: EXTERNAL_MANAGED resources: - - https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE + - [https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE](https://www.googleapis.com/compute/v1/projects/PROJECT_ID/global/forwardingRules/VICTIM_RULE) httpRules: - from: sources: diff --git a/src/pentesting-cloud/gcp-security/gcp-services/gcp-healthcare-enum.md b/src/pentesting-cloud/gcp-security/gcp-services/gcp-healthcare-enum.md index 63697d0b9b..96cf0be473 100644 --- a/src/pentesting-cloud/gcp-security/gcp-services/gcp-healthcare-enum.md +++ b/src/pentesting-cloud/gcp-security/gcp-services/gcp-healthcare-enum.md @@ -144,3 +144,4 @@ Repeat with `dicom-stores`, `hl7v2-stores`, and `consent-stores` as relevant. Ch 2. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access) 3. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging) 4. [FHIR store REST resource](https://docs.cloud.google.com/healthcare-api/docs/reference/rest/v1/projects.locations.datasets.fhirStores#FhirStore) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/gcp-unauthenticated-enum-and-access/gcp-healthcare-unauthenticated-enum.md b/src/pentesting-cloud/gcp-security/gcp-unauthenticated-enum-and-access/gcp-healthcare-unauthenticated-enum.md index c10a252ccf..f4fa889a5c 100644 --- a/src/pentesting-cloud/gcp-security/gcp-unauthenticated-enum-and-access/gcp-healthcare-unauthenticated-enum.md +++ b/src/pentesting-cloud/gcp-security/gcp-unauthenticated-enum-and-access/gcp-healthcare-unauthenticated-enum.md @@ -68,3 +68,4 @@ The analogous HL7v2 exposure needs `healthcare.hl7V2Messages.get` for a known me 2. [FHIR REST method authorization scopes](https://docs.cloud.google.com/healthcare-api/docs/reference/rest/v1/projects.locations.datasets.fhirStores.fhir/read) 3. [Controlling access to Cloud Healthcare API resources](https://docs.cloud.google.com/healthcare-api/docs/controlling-access) 4. [Cloud Healthcare API audit logging](https://docs.cloud.google.com/healthcare-api/docs/how-tos/audit-logging) +{{#include ../../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/gcp-security/permission-risk-categorizations.md b/src/pentesting-cloud/gcp-security/permission-risk-categorizations.md index 3cf0a9f590..0b607eb28a 100644 --- a/src/pentesting-cloud/gcp-security/permission-risk-categorizations.md +++ b/src/pentesting-cloud/gcp-security/permission-risk-categorizations.md @@ -1,5 +1,7 @@ # GCP permissions categories +{{#include ../../banners/hacktricks-training.md}} + The canonical [GCP categorization file](../../permission-categorizations/gcp.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS. - **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution. @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c +{{#include ../../banners/hacktricks-training.md}} diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration.md index 1f46c900d5..10092a47cb 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration +{{#include ../../banners/hacktricks-training.md}} + For attack paths from the enumerated permissions, continue with [Privilege Escalation](kubernetes-privilege-escalation/), [Post Exploitation](kubernetes-post-exploitation/), and [Persistence](kubernetes-persistence/). -{{#include ../../banners/hacktricks-training.md}} + Enumeration establishes **which identity you are using, what the API serves, which objects you can read, how those objects relate, and what operations the authorizer permits**. Begin with the [Kubernetes Basics](kubernetes-basic-information/) if the component and object model is unfamiliar. The pages below cover inventory and diagnostics; existing mutation examples are now in [Kubernetes API Object Operations](kubernetes-privilege-escalation/api-object-operations.md). diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/cluster-and-node-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/cluster-and-node-objects.md index 8713c1bc28..66cee69acc 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/cluster-and-node-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/cluster-and-node-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Cluster, Node & Resource Policy Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/node-permissions-and-status.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Use [namespace/scope basics](../kubernetes-basic-information/kubernetes-objects.md#namespaces-and-scope) and [node lifecycle basics](../kubernetes-basic-information/node-components.md#node-health-placement-and-local-evidence) to interpret these records. This page covers placement, health, coordination, and namespace resource controls that do not belong to workload templates or RBAC rules. diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/control-plane-and-node-services.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/control-plane-and-node-services.md index dc6816f6ec..debcae4f67 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/control-plane-and-node-services.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/control-plane-and-node-services.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Control-Plane & Node Services +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/node-permissions-and-status.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + ## Service and port inventory diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/controller-and-admission-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/controller-and-admission-objects.md index bf00d5437c..5ab3d8a0a5 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/controller-and-admission-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/controller-and-admission-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Controller & Admission Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/controllers-and-admission.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Read [extension and admission basics](../kubernetes-basic-information/control-plane-components.md#configuration-discovery-and-extension-boundaries) and [packaging concepts](../kubernetes-basic-information/access-and-common-concepts.md#helm-kustomize-and-gitops). A **controller** is a reconciliation process, not one universal Kubernetes object kind. Deployments, ReplicaSets, Jobs, and other workload controllers are enumerated on the [Workload Objects](workload-objects.md) page. Here, inventory extension registrations, request policy, and the objects consumed by installed controllers.[[1]](#references) diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/networking-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/networking-objects.md index 8332bcd0c5..970f4c7e4c 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/networking-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/networking-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Networking Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/storage-and-networking.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Networking objects describe **where clients enter, which routing rules apply, and which concrete backends receive traffic**. Read the [networking object basics](../kubernetes-basic-information/kubernetes-objects.md#networking-and-exposure-objects) and [DNS/routing concepts](../kubernetes-basic-information/access-and-common-concepts.md#dns-and-application-routing), then use the [connection and raw API helper](../kubernetes-enumeration.md#raw-api-without-kubectl) for the commands below. This page incorporates the former **Exposing Services in Kubernetes** page. diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/rbac-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/rbac-objects.md index faf489a0cd..cf408b79aa 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/rbac-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/rbac-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: RBAC Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/rbac-and-identities.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Start with the [identity and authorization basics](../kubernetes-basic-information/access-and-common-concepts.md#authentication-authorization-and-workload-identity). RBAC inventory explains **who is bound to which rules**. It is not a substitute for the [current-identity access reviews](../kubernetes-enumeration.md#get-my-current-permissions): an identity may be authorized to read workloads but forbidden to read the Roles that explain its access.[[1]](#references) diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/secrets-and-configmaps.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/secrets-and-configmaps.md index 5a156d54aa..e07a910a7b 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/secrets-and-configmaps.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/secrets-and-configmaps.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Secrets, ConfigMaps & Trust +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/secrets-and-configmaps.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Read [configuration and identity object basics](../kubernetes-basic-information/kubernetes-objects.md#configuration-and-secret-objects) and [trust basics](../kubernetes-basic-information/control-plane-components.md#pki-and-component-identities). Identify each object's **type, keys, consumers, delivery method, and owner/controller** before interpreting its security role. ServiceAccounts and their grants are on the [RBAC page](rbac-objects.md). diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/storage-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/storage-objects.md index b2a5a78e58..7bf0594f89 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/storage-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/storage-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Storage & Device Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/storage-and-networking.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Read [storage object basics](../kubernetes-basic-information/kubernetes-objects.md#volumes-and-storage-objects) and [node storage/device components](../kubernetes-basic-information/node-components.md#csi-devices-and-node-agents). Trace **Pod volume → PVC → PV → storage class/driver → attachment/node**, distinguishing requested storage from bound and mounted state. diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/workload-objects.md b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/workload-objects.md index 0a944cacec..61832e3d32 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/workload-objects.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-enumeration/workload-objects.md @@ -1,8 +1,10 @@ # Kubernetes Enumeration: Workload Objects +{{#include ../../../banners/hacktricks-training.md}} + For the privilege boundary and PoCs associated with these objects, see [K8s Privilege Escalation](../kubernetes-privilege-escalation/workload-and-pod-access.md); return here for inventory and configuration checks. -{{#include ../../../banners/hacktricks-training.md}} + Review the [basic workload object model](../kubernetes-basic-information/kubernetes-objects.md#workload-objects) first. Workload controllers belong here because their templates determine future Pods; admission and extension controllers have a [separate page](controller-and-admission-objects.md). diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/README.md b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/README.md index 45172eb64e..f7a8ca54a7 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/README.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/README.md @@ -1,8 +1,10 @@ # K8s - Post Exploitation +{{#include ../../../banners/hacktricks-training.md}} + After establishing a foothold, use [Privilege Escalation](../kubernetes-privilege-escalation/) for API permission abuse and [Persistence](../kubernetes-persistence/) for return paths. [Unauthenticated Access](../kubernetes-unauthenticated-access/) covers exposed entry points. -{{#include ../../../banners/hacktricks-training.md}} + Start here after establishing a Pod, Kubernetes identity, or node foothold. **Record the current principal and scope** before interpreting possible impact. Kubernetes API authorization, admission, node isolation, network policy, application authorization and cloud IAM are separate boundaries.[[1]](#references) diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/attacking-kubernetes-from-inside-a-pod.md b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/attacking-kubernetes-from-inside-a-pod.md index 0f180bf849..1260cb7da5 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/attacking-kubernetes-from-inside-a-pod.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/attacking-kubernetes-from-inside-a-pod.md @@ -1,8 +1,10 @@ # K8s - Post Exploitation from inside a Pod +{{#include ../../../banners/hacktricks-training.md}} + -{{#include ../../../banners/hacktricks-training.md}} + ## Starting from an existing Pod foothold diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/internal-network-attacks.md b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/internal-network-attacks.md index af52651ef0..415a077be2 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/internal-network-attacks.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/internal-network-attacks.md @@ -1,8 +1,10 @@ # K8s - Internal Network Attacks +{{#include ../../../banners/hacktricks-training.md}} + -{{#include ../../../banners/hacktricks-training.md}} + ## Trust boundaries and prerequisites diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-namespace-escalation.md b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-namespace-escalation.md index 5973ba2a59..4a3ec7e993 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-namespace-escalation.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-namespace-escalation.md @@ -1,8 +1,10 @@ # K8s - Namespace Escalation +{{#include ../../../banners/hacktricks-training.md}} + -{{#include ../../../banners/hacktricks-training.md}} + In Kubernetes it's pretty common that somehow **you manage to get inside a namespace** (by stealing some user credentials or by compromising a pod). However, usually you will be interested in **escalating to a different namespace as more interesting things can be found there**. Namespaces scope namespaced resources and RBAC bindings determine whether a principal can act in another namespace, so a foothold in one namespace does not imply access to another.[[1]](#references)[[3]](#references) diff --git a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-pivoting-to-clouds.md b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-pivoting-to-clouds.md index 0667997e19..d275f7163d 100644 --- a/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-pivoting-to-clouds.md +++ b/src/pentesting-cloud/kubernetes-security/kubernetes-post-exploitation/kubernetes-pivoting-to-clouds.md @@ -1,8 +1,10 @@ # K8s - Pivoting to Clouds +{{#include ../../../banners/hacktricks-training.md}} + -{{#include ../../../banners/hacktricks-training.md}} + ## Kubernetes and cloud identity boundaries diff --git a/src/pentesting-cloud/kubernetes-security/permission-risk-categorizations.md b/src/pentesting-cloud/kubernetes-security/permission-risk-categorizations.md index 5788965894..6558177107 100644 --- a/src/pentesting-cloud/kubernetes-security/permission-risk-categorizations.md +++ b/src/pentesting-cloud/kubernetes-security/permission-risk-categorizations.md @@ -1,5 +1,7 @@ # Kubernetes permissions categories +{{#include ../../banners/hacktricks-training.md}} + The canonical [Kubernetes categorization file](../../permission-categorizations/k8s.yaml) supplies the permission ratings used by CloudPEASS and Blue-CloudPEASS. - **Critical**: direct or almost independent privilege escalation, powerful identity grants, or privileged execution. @@ -20,3 +22,4 @@ Browse the complete categorization below, [download the YAML](../../permission-c +{{#include ../../banners/hacktricks-training.md}} diff --git a/src/permission-categorizations/README.md b/src/permission-categorizations/README.md index 69bf92409e..5f13b95df0 100644 --- a/src/permission-categorizations/README.md +++ b/src/permission-categorizations/README.md @@ -1,5 +1,7 @@ # Permission risk categorizations +{{#include ../banners/hacktricks-training.md}} + HackTricks Cloud maintains the shared permission severity data consumed by [CloudPEASS](https://github.com/peass-ng/CloudPEASS) and [Blue-CloudPEASS](https://github.com/peass-ng/Blue-CloudPEASS). Edit the canonical platform file here, rather than the generated copies in either consumer. - **Critical**: permissions that directly, or almost independently, grant powerful privileges, mint an identity, or enable privileged execution. @@ -34,3 +36,4 @@ Every Monday, both consumer repositories check out the current `master` of this To update locally in a consumer, run `python scripts/sync_hacktricks_permissions.py --book-root /path/to/hacktricks-cloud`. Add `--check` to detect stale copies without writing them. Source fetching in both consumers retries five times with bounded checkout deadlines and increasing delays. Incomplete downloads stay in temporary directories; exhausted retries leave the existing bundled data unchanged. +{{#include ../banners/hacktricks-training.md}}