GCP - Cloudidentity Privesc

Support HackTricks

Cloudidentity

Kwa maelezo zaidi kuhusu huduma ya cloudidentity, angalia ukurasa huu:

GCP - IAM, Principals & Org Policies Enum

Ongeza mwenyewe kwenye kundi

Ikiwa mtumiaji wako ana ruhusa za kutosha au kundi limewekwa vibaya, anaweza kuwa na uwezo wa kujifanya kuwa mwanachama wa kundi jipya:

gcloud identity groups memberships add --group-email <email> --member-email <email> [--roles OWNER]
# If --roles isn't specified you will get MEMBER

Badilisha uanachama wa kikundi

Ikiwa mtumiaji wako ana ruhusa za kutosha au kikundi kimewekwa vibaya, anaweza kuwa MMILIKI wa kikundi ambacho ni mwanachama wake:

# Check the current membership level
gcloud identity groups memberships describe --member-email <email> --group-email <email>

# If not OWNER try
gcloud identity groups memberships modify-membership-roles --group-email <email> --member-email <email> --add-roles=OWNER
Support HackTricks

Last updated