Skip to content

Latest commit

 

History

History
60 lines (38 loc) · 3.42 KB

aws-directory-services-privesc.md

File metadata and controls

60 lines (38 loc) · 3.42 KB

AWS - Directory Services Privesc

{% hint style="success" %} Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}

Directory Services

For more info about directory services check:

{% content-ref url="../aws-services/aws-directory-services-workdocs-enum.md" %} aws-directory-services-workdocs-enum.md {% endcontent-ref %}

ds:ResetUserPassword

This permission allows to change the password of any existent user in the Active Directory.
By default, the only existent user is Admin.

aws ds reset-user-password --directory-id <id> --user-name Admin --new-password Newpassword123.

AWS Management Console

It's possible to enable an application access URL that users from AD can access to login:

And then grant them an AWS IAM role for when they login, this way an AD user/group will have access over AWS management console:

There isn't apparently any way to enable the application access URL, the AWS Management Console and grant permission

{% hint style="success" %} Learn & practice AWS Hacking:HackTricks Training AWS Red Team Expert (ARTE)
Learn & practice GCP Hacking: HackTricks Training GCP Red Team Expert (GRTE)

Support HackTricks
{% endhint %}