Commit Graph

742 Commits

Author SHA1 Message Date
carlospolop
5775dd889f f 2025-10-25 17:36:44 +02:00
SirBroccoli
fbc88db666 Merge pull request #227 from HackTricks-wiki/update_Cloud_Discovery_With_AzureHound_20251025_011739
Cloud Discovery With AzureHound
2025-10-25 17:35:49 +02:00
SirBroccoli
6e9d109c8e Add new AWS post exploitation entries to SUMMARY.md 2025-10-25 17:35:38 +02:00
HackTricks News Bot
2a67405a78 Add content from: Cloud Discovery With AzureHound 2025-10-25 01:21:33 +00:00
SirBroccoli
a41bcbce89 Merge pull request #226 from AI-redteam/mwaa-post-exploitation
Mwaa post exploitation
2025-10-23 23:50:25 +02:00
Ben
3f8aa12ce9 Update README to specify Airflow DAG permissions
Clarified that all Airflow DAGs run with the execution role's permissions.
2025-10-23 16:26:48 -05:00
Ben
8c472fbf01 Revise README for AWS MWAA execution role vulnerability
Updated README to reflect the AWS MWAA execution role vulnerability and its implications for security, including detailed attack vectors
2025-10-23 16:25:37 -05:00
carlospolop
b0d0266670 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2025-10-23 21:30:26 +02:00
carlospolop
d56be2b9b2 f 2025-10-23 21:30:22 +02:00
Ben
65a1490ad0 Update README to clarify policy tightening process
Clarified the process of tightening the policy after deployment and the implications for defenders.
2025-10-23 13:24:27 -05:00
Ben
0d4fb441a9 Add README for AWS MWAA post-exploitation
fix location and structure
2025-10-23 13:20:36 -05:00
SirBroccoli
92e958069d Merge pull request #225 from JaimePolop/master
update
2025-10-23 15:41:21 +02:00
SirBroccoli
98e8a9cc67 Merge branch 'master' into master 2025-10-23 15:41:13 +02:00
SirBroccoli
83306f353e Merge pull request #222 from HackTricks-wiki/update_FlareProx__Deploy_Cloudflare_Worker_pass-through_p_20251014_125039
FlareProx Deploy Cloudflare Worker pass-through proxies for ...
2025-10-23 15:27:54 +02:00
SirBroccoli
9f2ba6206d Merge branch 'master' into update_FlareProx__Deploy_Cloudflare_Worker_pass-through_p_20251014_125039 2025-10-23 15:27:47 +02:00
SirBroccoli
9665e1fced Update cloudflare-workers-pass-through-proxy-ip-rotation.md 2025-10-23 15:26:40 +02:00
carlospolop
400cf2a607 f 2025-10-23 15:15:45 +02:00
carlospolop
06c0c04ebd reorg bedrock 2025-10-23 14:16:30 +02:00
SirBroccoli
98eb150b91 Merge pull request #221 from HackTricks-wiki/update_When_AI_Remembers_Too_Much___Persistent_Behaviors__20251010_011705
When AI Remembers Too Much – Persistent Behaviors in Agents’...
2025-10-23 14:12:19 +02:00
SirBroccoli
468bd28887 Fix XML delimiter formatting and enhance security details
Updated formatting of XML delimiters in the documentation to use backticks for clarity. Enhanced explanations regarding memory injection vulnerabilities and defensive measures.
2025-10-23 14:11:10 +02:00
SirBroccoli
d4d7511794 Merge pull request #220 from HackTricks-wiki/update_Skimming_Credentials_with_Azure_s_Front_Door_WAF_20251009_182735
Skimming Credentials with Azure's Front Door WAF
2025-10-23 14:05:38 +02:00
SirBroccoli
45b2e5e0a8 Update az-front-door.md 2025-10-23 14:05:23 +02:00
JaimePolop
e7a5f0fe28 cloudfront 2025-10-23 13:46:06 +02:00
Jaime Polop
1a856147be Merge branch 'HackTricks-wiki:master' into master 2025-10-23 13:10:02 +02:00
carlospolop
47c4cdb89b f 2025-10-23 12:53:05 +02:00
carlospolop
e09246386b f 2025-10-23 12:48:56 +02:00
carlospolop
8f646225ac f 2025-10-23 12:34:04 +02:00
carlospolop
ffda2bfb9c f 2025-10-23 12:30:35 +02:00
carlospolop
ff06c914fc f 2025-10-23 12:21:23 +02:00
JaimePolop
e4e6a409ce update 2025-10-22 23:26:58 +02:00
Ben
6fc8a8126e Add AWS MWAA post-exploitation documentation
Document the security risks and attack vectors associated with AWS MWAA's execution role, including data exfiltration and command and control channels.
2025-10-21 18:46:40 -05:00
carlospolop
08c2e42b76 f 2025-10-17 17:37:06 +02:00
HackTricks News Bot
01e37a9b81 Add content from: FlareProx: Deploy Cloudflare Worker pass-through proxies for...
- Remove searchindex.js (auto-generated file)
2025-10-14 12:54:14 +00:00
carlospolop
1719f8ed3c f 2025-10-13 22:42:54 +02:00
HackTricks News Bot
95d13f8b89 Add content from: When AI Remembers Too Much – Persistent Behaviors in Agents’...
- Remove searchindex.js (auto-generated file)
2025-10-10 01:20:09 +00:00
HackTricks News Bot
123b37d1f3 Add content from: Skimming Credentials with Azure's Front Door WAF
- Remove searchindex.js (auto-generated file)
2025-10-09 18:29:08 +00:00
carlospolop
9df8a4ac92 organize aws + new attacks 2025-10-09 12:26:40 +02:00
carlospolop
6dd86b2c9e rds post recheck 2025-10-07 17:28:10 +02:00
carlospolop
95302db34c AWS RDS post-exploitation: Out-of-band SQL via Data API + master password reset (Aurora) 2025-10-07 14:04:48 +02:00
SirBroccoli
90bd042880 Merge pull request #219 from JaimePolop/master
IAM and KMS Post Exploitation extended
2025-10-07 11:02:17 +02:00
SirBroccoli
1077cf6f89 Update AWS KMS post-exploitation documentation
Clarified KMS policy restrictions and updated ransomware sections.
2025-10-07 11:02:01 +02:00
carlospolop
27fd007fdd lambda attacks recheck 2025-10-07 00:41:18 +02:00
JaimePolop
29e379d07d IAM and KMS Post Exploitation extended 2025-10-06 19:01:11 +02:00
carlospolop
83663e4f98 dynamoDB attacks recheck 2025-10-06 13:14:59 +02:00
carlospolop
b5b72b0d26 Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2025-10-06 11:53:38 +02:00
carlospolop
0f213ea2db aws secrets manager recheck 2025-10-06 11:53:33 +02:00
SirBroccoli
35eafd8d54 Merge pull request #218 from JaimePolop/master
Secrets manager new attacks
2025-10-04 11:04:02 +02:00
SirBroccoli
9508f50485 Update aws-secrets-manager-privesc.md 2025-10-04 11:03:30 +02:00
SirBroccoli
e188809f70 Update aws-secrets-manager-post-exploitation.md 2025-10-04 11:02:17 +02:00
carlospolop
4bc4e19891 f 2025-10-04 02:09:51 +02:00