AWS - Accounts Unauthenticated Enum

Support HackTricks

Account IDs

Ikiwa una lengo kuna njia za kujaribu kubaini nambari za akaunti za akaunti zinazohusiana na lengo.

Brute-Force

Unaunda orodha ya nambari za akaunti zinazoweza na majina ya utambulisho na kuziangalia.

# Check if an account ID exists
curl -v https://<acount_id>.signin.aws.amazon.com
## If response is 404 it doesn't, if 200, it exists
## It also works from account aliases
curl -v https://vodafone-uk2.signin.aws.amazon.com

You can automate this process with this tool.

OSINT

Tafuta urls ambazo zina <alias>.signin.aws.amazon.com zikiwa na alias inayohusiana na shirika.

Marketplace

Ikiwa muuzaji ana instances katika soko, unaweza kupata id ya mmiliki (id ya akaunti) ya akaunti ya AWS aliyotumia.

Snapshots

  • Public EBS snapshots (EC2 -> Snapshots -> Public Snapshots)

  • RDS public snapshots (RDS -> Snapshots -> All Public Snapshots)

  • Public AMIs (EC2 -> AMIs -> Public images)

Errors

Ujumbe mwingi wa makosa ya AWS (hata ufikiaji umekataliwa) utaeleza hiyo taarifa.

References

Support HackTricks

Last updated