Commit Graph

859 Commits

Author SHA1 Message Date
Oussama Ait Manssour
4557349141 docs(aws): add AgentCore Code Interpreter role pivot privesc 2026-02-12 18:35:30 +01:00
Oussama Ait Manssour
9f57fc7119 Rename src/pentesting-cloud/aws-security/aws-privilege-escalation/src/pentesting-cloud/aws-security /aws-bedrock-agentcore-privesc.md to src/pentesting-cloud/aws-security/aws-privilege-escalation/aws-bedrock-agentcore-privesc/README.md 2026-02-12 11:04:17 +01:00
Oussama Ait Manssour
70738d211e Revise AWS Bedrock AgentCore Code Interpreter documentation
Updated the AWS Bedrock AgentCore documentation to clarify the Code Interpreter Role Pivot technique, including details on preconditions, required IAM actions, exploitation flow, and mitigation strategies.
2026-02-12 00:06:33 +01:00
Carlos Polop
d3f02fa469 f 2026-02-11 12:56:08 +01:00
Carlos Polop
6918c5539d f 2026-02-05 13:33:06 +01:00
Carlos Polop
a539034c29 f 2026-02-05 13:15:58 +01:00
Carlos Polop
886bd7bee9 change navbar 2026-02-05 00:44:00 +01:00
Carlos Polop
9e28d1f000 f 2026-02-04 11:27:07 +01:00
Carlos Polop
6e2e489c39 f 2026-02-04 11:17:02 +01:00
Carlos Polop
a5e792e60a PRs public codebuild abuse 2026-02-03 13:42:01 +01:00
Carlos Polop
6d17062d44 improve style 2026-01-28 15:05:04 +01:00
Carlos Polop
8c1b0c4522 fix 2026-01-28 10:44:05 +01:00
Carlos Polop
b6082c0f47 Fix CloudFront invalidation globbing 2026-01-26 16:08:11 +01:00
Carlos Polop
583de4835d Test hbs invalidation 2026-01-26 16:06:53 +01:00
Carlos Polop
924282288f Revert cache invalidation test comment 2026-01-26 15:48:18 +01:00
Carlos Polop
17ab1baa9a Fix CloudFront invalidation workflow triggers 2026-01-26 15:47:49 +01:00
Carlos Polop
32e189ed82 Pin mdBook in image and add CloudFront invalidation workflow 2026-01-26 15:46:25 +01:00
Carlos Polop
7ea6486f3f fix expandables on index 2026-01-26 15:28:31 +01:00
Carlos Polop
e359bef3d1 fix ad in mobile version 2026-01-26 11:47:45 +01:00
SirBroccoli
98363bcd9e Merge pull request #250 from SrFlipFlop/stepfunctions-old-cli
Corrected AWS CLI syntax for Step Functions
2026-01-26 01:50:18 +01:00
Carlos Polop
39346f3b9e fix ui 2026-01-26 01:44:52 +01:00
SrFlipFlop
26a50a62d0 While I was doing the ARTE lab on Step Functions, I noticed that some Hacktricks commands were incorrect or should be using an earlier version of AWS CLI. Changed aws states for aws stepfunctions. 2026-01-22 17:36:06 +01:00
Carlos Polop
349afe720a Restore enumeration commands in Azure network doc 2026-01-21 21:36:00 +01:00
HackTricks News Bot
5642a68eb9 Add content from: DNS OverDoS: Are Private Endpoints Too Private? 2026-01-21 21:34:34 +01:00
SirBroccoli
4ba2a825c6 Merge pull request #248 from Jacob-Ham/automation-accounts-addition
Added azure rest command for webhook creation.
2026-01-21 21:28:23 +01:00
Carlos Polop
58b2dc7621 f 2026-01-21 21:14:36 +01:00
Carlos Polop
12bbfb1041 f 2026-01-21 21:07:17 +01:00
Carlos Polop
8ffaedacfa a 2026-01-21 21:03:44 +01:00
Carlos Polop
7b66f39ce6 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2026-01-18 23:17:19 +01:00
Carlos Polop
ffaced98d4 f 2026-01-18 23:17:17 +01:00
Jacob H
9d5350dc2e Added runOn key for hybrid worker.
Updated az rest command to specify hybrid worker with runOn
2026-01-18 10:14:15 -06:00
Jacob H
b782a5ebb8 Added azure rest command for webhook creation.
Clarified commands for creating webhooks in Azure Automation by adding the Azure CLI REST method.
2026-01-18 09:50:01 -06:00
SirBroccoli
6ced6574a0 Merge pull request #246 from HackTricks-wiki/update_Infiltrating_the_AWS_Console_Supply_Chain__Hijacki_20260116_124313
Infiltrating the AWS Console Supply Chain Hijacking Core AWS...
2026-01-18 15:58:08 +01:00
SirBroccoli
c716f0a3ba Merge pull request #240 from HackTricks-wiki/update_Holiday_Hack_Challenge_2025__Act_1__-_Spare_Key_20260106_124916
Holiday Hack Challenge 2025 (Act 1) - Spare Key
2026-01-18 15:57:07 +01:00
SirBroccoli
7f7f8b3183 Merge branch 'master' into update_Holiday_Hack_Challenge_2025__Act_1__-_Spare_Key_20260106_124916 2026-01-18 15:56:29 +01:00
Carlos Polop
1bae0f14cc Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2026-01-18 12:49:28 +01:00
Carlos Polop
a65ebe2aea gh cache 2026-01-18 12:49:25 +01:00
SirBroccoli
e8e5deb803 Merge pull request #245 from Jacob-Ham/master
Added AzCLI command for retrieving static web app secrets
2026-01-18 12:44:44 +01:00
Carlos Polop
df0aaa9a31 clier 2026-01-18 12:44:12 +01:00
Carlos Polop
d925f6f442 jenkins update 2026-01-17 17:44:00 +01:00
HackTricks News Bot
a41dc4c89f Add content from: Infiltrating the AWS Console Supply Chain: Hijacking Core AW... 2026-01-16 12:44:49 +00:00
Jacob H
f3d0f7a6c2 Merge pull request #1 from Jacob-Ham/Jacob-Ham-staticwebapp-command-addition
Added AzCLI command for retrieving static web app secrets
2026-01-13 13:33:57 -05:00
Jacob H
470a130c16 Added AzCLI command for retrieving static web app secrets 2026-01-13 12:29:34 -06:00
SirBroccoli
ce30a61d98 Update az-storage.md 2026-01-13 15:55:00 +01:00
SirBroccoli
76162d9fa6 Merge pull request #239 from HackTricks-wiki/update_Holiday_Hack_Challenge_2025__Blob_Storage__Storage_20260106_124314
Holiday Hack Challenge 2025 Blob Storage (Storage Secrets)
2026-01-13 15:52:35 +01:00
Carlos Polop
b5aa9c1fdf new ecs attack 2026-01-13 15:06:31 +01:00
SirBroccoli
b5d79daf09 Merge pull request #238 from HackTricks-wiki/update_ECS_on_EC2__Covering_Gaps_in_IMDS_Hardening_20251229_015227
ECS on EC2 Covering Gaps in IMDS Hardening
2026-01-13 14:55:32 +01:00
SirBroccoli
5d8a658c6e Merge pull request #237 from HackTricks-wiki/update_A_Survey_of_2024_2025_Open_Source_Supply_Chain_Com_20251229_014719
A Survey of 2024–2025 Open‑Source Supply‑Chain Compromises a...
2026-01-13 14:27:20 +01:00
SirBroccoli
3927bf4432 Merge pull request #242 from ryotaromatsui/rds-CreateBlueGreenDeployment_passrole_privsc
arte-ryotaro
2026-01-13 14:23:44 +01:00
Carlos Polop
95165880b2 f 2026-01-13 13:48:03 +01:00