AWS - Directory Services Privesc

Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)!

Other ways to support HackTricks:

Directory Services

For more info about directory services check:

pageAWS - Directory Services / WorkDocs Enum

ds:ResetUserPassword

This permission allows to change the password of any existent user in the Active Directory. By default, the only existent user is Admin.

aws ds reset-user-password --directory-id <id> --user-name Admin --new-password Newpassword123.

AWS Management Console

It's possible to enable an application access URL that users from AD can access to login:

And then grant them an AWS IAM role for when they login, this way an AD user/group will have access over AWS management console:

There isn't apparently any way to enable the application access URL, the AWS Management Console and grant permission

Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)!

Other ways to support HackTricks:

Last updated