mirror of
https://github.com/HackTricks-wiki/hacktricks-cloud.git
synced 2026-01-27 15:24:32 -08:00
Translated ['src/README.md', 'src/banners/hacktricks-training.md', 'src/
This commit is contained in:
@@ -1,37 +1,33 @@
|
||||
# AWS - Lightsail Persistence
|
||||
# AWS - Lightsail Persistensie
|
||||
|
||||
{{#include ../../../banners/hacktricks-training.md}}
|
||||
|
||||
## Lightsail
|
||||
|
||||
For more information check:
|
||||
Vir meer inligting, kyk:
|
||||
|
||||
{{#ref}}
|
||||
../aws-services/aws-lightsail-enum.md
|
||||
{{#endref}}
|
||||
|
||||
### Download Instance SSH keys & DB passwords
|
||||
### Laai Instansie SSH sleutels & DB wagwoorde af
|
||||
|
||||
They won't be changed probably so just having them is a good option for persistence
|
||||
Hulle sal waarskynlik nie verander word nie, so om hulle te hê is 'n goeie opsie vir persistensie
|
||||
|
||||
### Backdoor Instances
|
||||
### Agterdeur Instansies
|
||||
|
||||
An attacker could get access to the instances and backdoor them:
|
||||
'n Aanvaller kan toegang tot die instansies verkry en hulle agterdeur:
|
||||
|
||||
- Using a traditional **rootkit** for example
|
||||
- Adding a new **public SSH key**
|
||||
- Expose a port with port knocking with a backdoor
|
||||
- Gebruik 'n tradisionele **rootkit** byvoorbeeld
|
||||
- Voeg 'n nuwe **publieke SSH-sleutel** by
|
||||
- Stel 'n poort bloot met poortklop met 'n agterdeur
|
||||
|
||||
### DNS persistence
|
||||
### DNS persistensie
|
||||
|
||||
If domains are configured:
|
||||
As domeine gekonfigureer is:
|
||||
|
||||
- Create a subdomain pointing your IP so you will have a **subdomain takeover**
|
||||
- Create **SPF** record allowing you to send **emails** from the domain
|
||||
- Configure the **main domain IP to your own one** and perform a **MitM** from your IP to the legit ones
|
||||
- Skep 'n subdomein wat jou IP aandui sodat jy 'n **subdomein oorneem** sal hê
|
||||
- Skep **SPF** rekord wat jou toelaat om **e-posse** van die domein te stuur
|
||||
- Konfigureer die **hoofdomein IP na jou eie** en voer 'n **MitM** uit van jou IP na die wettige een
|
||||
|
||||
{{#include ../../../banners/hacktricks-training.md}}
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user