AWS - Accounts Unauthenticated Enum
Last updated
Last updated
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)
Ikiwa una lengo kuna njia za kujaribu kubaini vitambulisho vya akaunti za akaunti zinazohusiana na lengo.
Unaunda orodha ya vitambulisho vya akaunti na majina ya utani na kuangalia.
You can automate this process with this tool.
Tafuta urls ambazo zina <alias>.signin.aws.amazon.com
zikiwa na alias inayohusiana na shirika.
Ikiwa muuzaji ana instances katika soko, unaweza kupata id ya mmiliki (id ya akaunti) ya akaunti ya AWS aliyoitumia.
Public EBS snapshots (EC2 -> Snapshots -> Public Snapshots)
RDS public snapshots (RDS -> Snapshots -> All Public Snapshots)
Public AMIs (EC2 -> AMIs -> Public images)
Ujumbe mwingi wa makosa ya AWS (hata ufikiaji umekataliwa) utatoa taarifa hiyo.
Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE) Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)