AWS - Elastic Beanstalk Privesc
Elastic Beanstalk
Maelezo zaidi kuhusu Elastic Beanstalk yamo:
AWS - Elastic Beanstalk EnumIli kutekeleza vitendo vyenye hisia kwenye Beanstalk, utahitaji kuwa na idhini nyingi za hisia katika huduma nyingi tofauti. Unaweza kuchunguza kwa mfano idhini zilizotolewa kwa arn:aws:iam::aws:policy/AdministratorAccess-AWSElasticBeanstalk
elasticbeanstalk:RebuildEnvironment
, ruhusa za kuandika S3 & nyingine nyingi
elasticbeanstalk:RebuildEnvironment
, ruhusa za kuandika S3 & nyingine nyingiKwa ruhusa za kuandika kwenye kisanduku cha S3 kinachohifadhi mimbo ya mazingira na ruhusa za kujenga upya maombi (inahitajika elasticbeanstalk:RebuildEnvironment
na zingine kadhaa zinazohusiana na S3
, EC2
na Cloudformation
), unaweza kurekebisha mimbo, kujenga upya programu na wakati ujao unapofikia programu hiyo ita utekeleza kificho chako kipya, ikiruhusu mshambuliaji kudhoofisha programu na sifa za jukumu la IAM zake.
elasticbeanstalk:CreateApplication
, elasticbeanstalk:CreateEnvironment
, elasticbeanstalk:CreateApplicationVersion
, elasticbeanstalk:UpdateEnvironment
, iam:PassRole
, na zaidi...
elasticbeanstalk:CreateApplication
, elasticbeanstalk:CreateEnvironment
, elasticbeanstalk:CreateApplicationVersion
, elasticbeanstalk:UpdateEnvironment
, iam:PassRole
, na zaidi...Zilizotajwa pamoja na idadi kadhaa ya ruhusa za S3
, EC2
, cloudformation
, autoscaling
na elasticloadbalancing
ni muhimu kwa kujenga mazingira ya Elastic Beanstalk kutoka mwanzo.
Unda maombi ya AWS Elastic Beanstalk:
Unda mazingira ya AWS Elastic Beanstalk (majukwaa yanayoungwa mkono):
Ikiwa mazingira tayari yameundwa na hautaki kuunda jipya, unaweza tu kuboresha lile lililopo.
Pakia nambari ya programu yako na mahitaji yake katika faili ya ZIP:
Pakia faili la ZIP kwenye ndoo ya S3:
Unda toleo la programu ya AWS Elastic Beanstalk:
Weka toleo la maombi kwenye mazingira yako ya AWS Elastic Beanstalk:
elasticbeanstalk:UndaMsimboWaMaombi
, elasticbeanstalk:SasishaMazingira
, cloudformation:PataKiolesura
, cloudformation:ElezaVifaaVyaMfumo
, cloudformation:ElezaKifaaChaMfumo
, autoscaling:ElezaVikundiVyaUkubwa
, autoscaling:SitishaMichakato
, autoscaling:SitishaMichakato
elasticbeanstalk:UndaMsimboWaMaombi
, elasticbeanstalk:SasishaMazingira
, cloudformation:PataKiolesura
, cloudformation:ElezaVifaaVyaMfumo
, cloudformation:ElezaKifaaChaMfumo
, autoscaling:ElezaVikundiVyaUkubwa
, autoscaling:SitishaMichakato
, autoscaling:SitishaMichakato
Kwanza kabisa unahitaji kuunda mazingira halali ya Beanstalk na msimbo ungependa kukimbia kwa mwendazake kufuata hatua za awali. Kuna uwezekano wa zipu rahisi inayojumuisha faili hizi 2:
Baada ya kuwa na mazingira yako ya Beanstalk yakiendesha rev shell yako, ni wakati wa kuhamisha kwa mazingira ya waathiriwa. Ili kufanya hivyo, unahitaji kuboresha Sera ya Ndoo ya ndoo yako ya S3 ya beanstalk ili mwathiriwa aweze kufikia (Tafadhali kumbuka kuwa hii itafungua Ndoo kwa KILA MTU):
Last updated