Commit Graph

769 Commits

Author SHA1 Message Date
carlospolop
3333cb3315 f 2025-11-22 20:05:24 +01:00
carlospolop
6cd2d68471 gcp 2025-11-22 19:35:20 +01:00
carlospolop
75115ef884 f 2025-11-22 12:40:12 +01:00
carlospolop
d9feef72f3 f 2025-11-21 15:14:19 +01:00
carlospolop
b510992854 f 2025-11-21 13:42:46 +01:00
carlospolop
b054fe536d f 2025-11-19 18:39:42 +01:00
carlospolop
84b8efa343 dynamic groups 2025-11-19 18:15:02 +01:00
carlospolop
d25a46d41c bigtable 2025-11-19 15:32:45 +01:00
carlospolop
7c16632a63 f 2025-11-17 16:31:36 +01:00
carlospolop
77427a069a k8s tools 2025-11-17 13:12:03 +01:00
SirBroccoli
6726a5eee4 Merge pull request #231 from HackTricks-wiki/update_Vulnerabilities_in_LUKS2_disk_encryption_for_confi_20251030_130547
Vulnerabilities in LUKS2 disk encryption for confidential VM...
2025-11-15 17:27:25 +01:00
SirBroccoli
293ae05fb9 Update pentesting-cloud-methodology.md structure
Removed sections on Attack Graph and Office365, and added a section on Common Cloud Security Features.
2025-11-15 17:27:13 +01:00
SirBroccoli
a02f8ad45e Update SUMMARY.md 2025-11-15 17:25:29 +01:00
carlospolop
a9a58a9d84 f 2025-11-15 12:44:34 +01:00
SirBroccoli
449be62264 Merge pull request #230 from searabbitx/master
arte-sp00ky
2025-11-01 11:51:55 +01:00
SirBroccoli
63c74776fc Merge pull request #232 from alecclyde/patch-1
Fix typo in README regarding cloud pivoting
2025-11-01 11:44:53 +01:00
Alec Chappell
9c2191ecae Fix typo in README regarding cloud pivoting
typo to 'cloud'
2025-10-31 10:10:38 -04:00
HackTricks News Bot
7cc4479e64 Add content from: Vulnerabilities in LUKS2 disk encryption for confidential VM... 2025-10-30 13:14:27 +00:00
searabbit
9ae10ba9d7 Add db cluster enumeration commands to aws-relational-database-rds-enum 2025-10-30 08:52:49 +01:00
searabbit
9a4644dc0f Add rds cluster snapshots enumeration commands to aws-rds-unauthenticated-enum 2025-10-30 08:46:18 +01:00
carlospolop
3a7f081f42 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2025-10-26 00:25:07 +02:00
carlospolop
d4dcccb82d f 2025-10-26 00:25:04 +02:00
SirBroccoli
9c558ff9df Merge pull request #228 from HackTricks-wiki/update_Breaking_MCP_Server_Hosting__Build-Context_Path_Tr_20251025_123530
Breaking MCP Server Hosting Build-Context Path Traversal to ...
2025-10-25 17:39:38 +02:00
SirBroccoli
469887faef Merge branch 'master' into update_Breaking_MCP_Server_Hosting__Build-Context_Path_Tr_20251025_123530 2025-10-25 17:39:32 +02:00
SirBroccoli
9968ab5901 Update SUMMARY.md 2025-10-25 17:39:11 +02:00
SirBroccoli
92ec260969 Update docker-build-context-abuse.md 2025-10-25 17:38:18 +02:00
carlospolop
5775dd889f f 2025-10-25 17:36:44 +02:00
SirBroccoli
fbc88db666 Merge pull request #227 from HackTricks-wiki/update_Cloud_Discovery_With_AzureHound_20251025_011739
Cloud Discovery With AzureHound
2025-10-25 17:35:49 +02:00
SirBroccoli
6e9d109c8e Add new AWS post exploitation entries to SUMMARY.md 2025-10-25 17:35:38 +02:00
HackTricks News Bot
1c91bb9cf9 Add content from: Breaking MCP Server Hosting: Build-Context Path Traversal to... 2025-10-25 12:37:57 +00:00
HackTricks News Bot
2a67405a78 Add content from: Cloud Discovery With AzureHound 2025-10-25 01:21:33 +00:00
SirBroccoli
a41bcbce89 Merge pull request #226 from AI-redteam/mwaa-post-exploitation
Mwaa post exploitation
2025-10-23 23:50:25 +02:00
Ben
3f8aa12ce9 Update README to specify Airflow DAG permissions
Clarified that all Airflow DAGs run with the execution role's permissions.
2025-10-23 16:26:48 -05:00
Ben
8c472fbf01 Revise README for AWS MWAA execution role vulnerability
Updated README to reflect the AWS MWAA execution role vulnerability and its implications for security, including detailed attack vectors
2025-10-23 16:25:37 -05:00
carlospolop
b0d0266670 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2025-10-23 21:30:26 +02:00
carlospolop
d56be2b9b2 f 2025-10-23 21:30:22 +02:00
Ben
65a1490ad0 Update README to clarify policy tightening process
Clarified the process of tightening the policy after deployment and the implications for defenders.
2025-10-23 13:24:27 -05:00
Ben
0d4fb441a9 Add README for AWS MWAA post-exploitation
fix location and structure
2025-10-23 13:20:36 -05:00
SirBroccoli
92e958069d Merge pull request #225 from JaimePolop/master
update
2025-10-23 15:41:21 +02:00
SirBroccoli
98e8a9cc67 Merge branch 'master' into master 2025-10-23 15:41:13 +02:00
SirBroccoli
83306f353e Merge pull request #222 from HackTricks-wiki/update_FlareProx__Deploy_Cloudflare_Worker_pass-through_p_20251014_125039
FlareProx Deploy Cloudflare Worker pass-through proxies for ...
2025-10-23 15:27:54 +02:00
SirBroccoli
9f2ba6206d Merge branch 'master' into update_FlareProx__Deploy_Cloudflare_Worker_pass-through_p_20251014_125039 2025-10-23 15:27:47 +02:00
SirBroccoli
9665e1fced Update cloudflare-workers-pass-through-proxy-ip-rotation.md 2025-10-23 15:26:40 +02:00
carlospolop
400cf2a607 f 2025-10-23 15:15:45 +02:00
carlospolop
06c0c04ebd reorg bedrock 2025-10-23 14:16:30 +02:00
SirBroccoli
98eb150b91 Merge pull request #221 from HackTricks-wiki/update_When_AI_Remembers_Too_Much___Persistent_Behaviors__20251010_011705
When AI Remembers Too Much – Persistent Behaviors in Agents’...
2025-10-23 14:12:19 +02:00
SirBroccoli
468bd28887 Fix XML delimiter formatting and enhance security details
Updated formatting of XML delimiters in the documentation to use backticks for clarity. Enhanced explanations regarding memory injection vulnerabilities and defensive measures.
2025-10-23 14:11:10 +02:00
SirBroccoli
d4d7511794 Merge pull request #220 from HackTricks-wiki/update_Skimming_Credentials_with_Azure_s_Front_Door_WAF_20251009_182735
Skimming Credentials with Azure's Front Door WAF
2025-10-23 14:05:38 +02:00
SirBroccoli
45b2e5e0a8 Update az-front-door.md 2025-10-23 14:05:23 +02:00
JaimePolop
e7a5f0fe28 cloudfront 2025-10-23 13:46:06 +02:00