GCP - Generic Permissions Privesc

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE) GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์ผ๋ฐ˜ ํฅ๋ฏธ๋กœ์šด ๊ถŒํ•œ

*.setIamPolicy

์‚ฌ์šฉ์ž๊ฐ€ setIamPolicy ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๊ฒฝ์šฐ, ํ•ด๋‹น ๋ฆฌ์†Œ์Šค์˜ IAM ์ •์ฑ…์„ ๋ณ€๊ฒฝํ•˜์—ฌ ํ•ด๋‹น ๋ฆฌ์†Œ์Šค์—์„œ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ถŒํ•œ์€ ์ฝ”๋“œ ์‹คํ–‰์„ ํ—ˆ์šฉํ•˜๋Š” ๋ฆฌ์†Œ์Šค์—์„œ ๋‹ค๋ฅธ ์ฃผ์ฒด๋กœ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค๋‹ˆ๋‹ค. iam.ServiceAccounts.actAs๊ฐ€ ํ•„์š”ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

  • cloudfunctions.functions.setIamPolicy

  • Cloud Function์˜ ์ •์ฑ…์„ ์ˆ˜์ •ํ•˜์—ฌ ์ž์‹ ์ด ํ˜ธ์ถœํ•  ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ๊ถŒํ•œ์„ ๊ฐ€์ง„ ๋ฆฌ์†Œ์Šค ์œ ํ˜•์ด ์ˆ˜์‹ญ ๊ฐœ ์žˆ์œผ๋ฉฐ, https://cloud.google.com/iam/docs/permissions-reference์—์„œ setIamPolicy๋ฅผ ๊ฒ€์ƒ‰ํ•˜์—ฌ ๋ชจ๋‘ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

*.create, *.update

์ด ๊ถŒํ•œ์€ ์ƒˆ ๋ฆฌ์†Œ์Šค๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ๊ธฐ์กด ๋ฆฌ์†Œ์Šค๋ฅผ ์—…๋ฐ์ดํŠธํ•˜์—ฌ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ค๋Š” ๋ฐ ๋งค์šฐ ์œ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๊ถŒํ•œ์€ ์„œ๋น„์Šค ๊ณ„์ •์— ๋Œ€ํ•ด iam.serviceAccounts.actAs ๊ถŒํ•œ์ด ์žˆ๋Š” ๊ฒฝ์šฐ ํŠนํžˆ ์œ ์šฉํ•˜๋ฉฐ, .create/.update ๊ถŒํ•œ์ด ์žˆ๋Š” ๋ฆฌ์†Œ์Šค๋Š” ์„œ๋น„์Šค ๊ณ„์ •์„ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

*ServiceAccount*

์ด ๊ถŒํ•œ์€ ์ผ๋ฐ˜์ ์œผ๋กœ ์ผ๋ถ€ ๋ฆฌ์†Œ์Šค์—์„œ ์„œ๋น„์Šค ๊ณ„์ •์— ์ ‘๊ทผํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ค๋‹ˆ๋‹ค (์˜ˆ: compute.instances.setServiceAccount). ์ด ๊ถŒํ•œ ์ƒ์Šน ๋ฒกํ„ฐ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ํ•˜์ง€๋งŒ ๊ฐ ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE) GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Last updated