AWS - Directory Services Privesc
Last updated
Last updated
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
For more info about directory services check:
AWS - Directory Services / WorkDocs Enumds:ResetUserPassword
This permission allows to change the password of any existent user in the Active Directory. By default, the only existent user is Admin.
It's possible to enable an application access URL that users from AD can access to login:
And then grant them an AWS IAM role for when they login, this way an AD user/group will have access over AWS management console:
There isn't apparently any way to enable the application access URL, the AWS Management Console and grant permission
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)