Commit Graph

538 Commits

Author SHA1 Message Date
SirBroccoli
d5284abf61 Merge pull request #257 from AI-redteam/gcp-workstations-privesc
Gcp workstations privesc & container escape [grte-bstevens]
2026-02-12 20:36:18 +01:00
SirBroccoli
08ca5b601d Merge pull request #258 from AMOussama/bedrock-agentcore-code-interpreter
arte-Oussama - Bedrock agentcore code interpreter
2026-02-12 20:36:02 +01:00
Oussama Ait Manssour
4557349141 docs(aws): add AgentCore Code Interpreter role pivot privesc 2026-02-12 18:35:30 +01:00
Carlos Polop
745851f56d f ht url 2026-02-12 14:18:33 +01:00
SirBroccoli
d319c5283b Merge pull request #254 from HackTricks-wiki/update_GatewayToHeaven__Finding_a_Cross-Tenant_Vulnerabil_20260203_185749
GatewayToHeaven Finding a Cross-Tenant Vulnerability in GCP'...
2026-02-12 14:10:09 +01:00
Carlos Polop
9b923592af Move Apigee post-exploitation technique into its own page 2026-02-12 14:06:56 +01:00
SirBroccoli
6d8fa0c2fc Merge pull request #256 from HackTricks-wiki/update_Trusting_Claude_With_a_Knife__Unauthorized_Prompt__20260206_184722
Trusting Claude With a Knife Unauthorized Prompt Injection t...
2026-02-12 14:04:54 +01:00
SirBroccoli
c8bd0b86fd Merge pull request #255 from MAAYTHM/patch-1
Fix typo in S3 encryption method
2026-02-12 14:01:52 +01:00
SirBroccoli
3c05bcfbf2 Merge pull request #253 from HackTricks-wiki/update_Threat_Actors_Using_AWS_WorkMail_in_Phishing_Campa_20260127_183842
Threat Actors Using AWS WorkMail in Phishing Campaigns
2026-02-12 13:30:45 +01:00
SirBroccoli
9f30d3f8e8 Merge pull request #252 from HackTricks-wiki/update_nodes_proxy_GET___Kubelet__exec_RCE_via_WebSocket__20260127_014641
nodes/proxy GET → Kubelet /exec RCE via WebSocket handshake ...
2026-02-12 13:20:29 +01:00
SirBroccoli
d4b7c719ea Merge pull request #251 from HackTricks-wiki/update_SharePointDumper_20260127_014432
SharePointDumper
2026-02-12 13:09:08 +01:00
Oussama Ait Manssour
9f57fc7119 Rename src/pentesting-cloud/aws-security/aws-privilege-escalation/src/pentesting-cloud/aws-security /aws-bedrock-agentcore-privesc.md to src/pentesting-cloud/aws-security/aws-privilege-escalation/aws-bedrock-agentcore-privesc/README.md 2026-02-12 11:04:17 +01:00
Oussama Ait Manssour
70738d211e Revise AWS Bedrock AgentCore Code Interpreter documentation
Updated the AWS Bedrock AgentCore documentation to clarify the Code Interpreter Role Pivot technique, including details on preconditions, required IAM actions, exploitation flow, and mitigation strategies.
2026-02-12 00:06:33 +01:00
Ben
2bb1292912 Remove countermeasures from GCP privilege escalation doc
Removed countermeasures section from GCP privilege escalation documentation.
2026-02-09 16:16:44 -06:00
Ben
0be98dc154 Remove hacktricks-training banner from documentation
Removed the inclusion of hacktricks-training banner from the GCP privilege escalation documentation.
2026-02-09 16:12:22 -06:00
Ben
6b1b2329c2 Clean up GCP Cloud Workstations privilege escalation doc
Removed introductory content and references related to Cloud Workstations.
2026-02-09 16:10:20 -06:00
Ben
4a16d25bfe Add GCP Cloud Workstations privesc guide
Add a new guide documenting privilege escalation paths for GCP Cloud Workstations. Covers Docker-in-Docker container breakout via /var/run/docker.sock, step-by-step escape to the host VM, stealing the VM service account token from IMDS, persistence by backdooring the host home, network pivot techniques, and recommended countermeasures. Includes reference to an automation script and training banners.
2026-02-09 16:08:37 -06:00
HackTricks News Bot
0d72508bc8 Add content from: Trusting Claude With a Knife: Unauthorized Prompt Injection ... 2026-02-06 18:53:46 +00:00
Carlos Polop
6918c5539d f 2026-02-05 13:33:06 +01:00
Carlos Polop
a539034c29 f 2026-02-05 13:15:58 +01:00
Aayush Samriya
ab13130748 Fix typo in S3 encryption method
This PR fixes a typo in the "Amazon Athena" section regarding supported S3 encryption methods.

The text currently states:
> "SSE-C and CSE-E are not supported."

"CSE-E" is not a valid AWS encryption acronym. The document previously defines **Client-side encryption with customer provided keys** as **CSE-C**.

Since Athena does not support client-side encryption where the key is managed entirely by the customer (without KMS), **CSE-C** is the correct term to pair with SSE-C as unsupported methods.
2026-02-05 11:29:39 +05:30
HackTricks News Bot
3b110bdefe Add content from: GatewayToHeaven: Finding a Cross-Tenant Vulnerability in GCP... 2026-02-03 19:00:44 +00:00
Carlos Polop
a5e792e60a PRs public codebuild abuse 2026-02-03 13:42:01 +01:00
HackTricks News Bot
6be7ed9238 Add content from: Threat Actors Using AWS WorkMail in Phishing Campaigns 2026-01-27 18:48:13 +00:00
HackTricks News Bot
e19da8e90c Add content from: nodes/proxy GET → Kubelet /exec RCE via WebSocket handshake ... 2026-01-27 01:48:53 +00:00
HackTricks News Bot
41b59810d8 Add content from: SharePointDumper 2026-01-27 01:46:05 +00:00
SrFlipFlop
26a50a62d0 While I was doing the ARTE lab on Step Functions, I noticed that some Hacktricks commands were incorrect or should be using an earlier version of AWS CLI. Changed aws states for aws stepfunctions. 2026-01-22 17:36:06 +01:00
Carlos Polop
349afe720a Restore enumeration commands in Azure network doc 2026-01-21 21:36:00 +01:00
HackTricks News Bot
5642a68eb9 Add content from: DNS OverDoS: Are Private Endpoints Too Private? 2026-01-21 21:34:34 +01:00
SirBroccoli
4ba2a825c6 Merge pull request #248 from Jacob-Ham/automation-accounts-addition
Added azure rest command for webhook creation.
2026-01-21 21:28:23 +01:00
Carlos Polop
12bbfb1041 f 2026-01-21 21:07:17 +01:00
Jacob H
9d5350dc2e Added runOn key for hybrid worker.
Updated az rest command to specify hybrid worker with runOn
2026-01-18 10:14:15 -06:00
Jacob H
b782a5ebb8 Added azure rest command for webhook creation.
Clarified commands for creating webhooks in Azure Automation by adding the Azure CLI REST method.
2026-01-18 09:50:01 -06:00
SirBroccoli
6ced6574a0 Merge pull request #246 from HackTricks-wiki/update_Infiltrating_the_AWS_Console_Supply_Chain__Hijacki_20260116_124313
Infiltrating the AWS Console Supply Chain Hijacking Core AWS...
2026-01-18 15:58:08 +01:00
SirBroccoli
7f7f8b3183 Merge branch 'master' into update_Holiday_Hack_Challenge_2025__Act_1__-_Spare_Key_20260106_124916 2026-01-18 15:56:29 +01:00
Carlos Polop
1bae0f14cc Merge branch 'master' of github.com:HackTricks-wiki/hacktricks-cloud 2026-01-18 12:49:28 +01:00
Carlos Polop
a65ebe2aea gh cache 2026-01-18 12:49:25 +01:00
SirBroccoli
e8e5deb803 Merge pull request #245 from Jacob-Ham/master
Added AzCLI command for retrieving static web app secrets
2026-01-18 12:44:44 +01:00
Carlos Polop
df0aaa9a31 clier 2026-01-18 12:44:12 +01:00
Carlos Polop
d925f6f442 jenkins update 2026-01-17 17:44:00 +01:00
HackTricks News Bot
a41dc4c89f Add content from: Infiltrating the AWS Console Supply Chain: Hijacking Core AW... 2026-01-16 12:44:49 +00:00
Jacob H
470a130c16 Added AzCLI command for retrieving static web app secrets 2026-01-13 12:29:34 -06:00
SirBroccoli
ce30a61d98 Update az-storage.md 2026-01-13 15:55:00 +01:00
SirBroccoli
76162d9fa6 Merge pull request #239 from HackTricks-wiki/update_Holiday_Hack_Challenge_2025__Blob_Storage__Storage_20260106_124314
Holiday Hack Challenge 2025 Blob Storage (Storage Secrets)
2026-01-13 15:52:35 +01:00
Carlos Polop
b5aa9c1fdf new ecs attack 2026-01-13 15:06:31 +01:00
SirBroccoli
b5d79daf09 Merge pull request #238 from HackTricks-wiki/update_ECS_on_EC2__Covering_Gaps_in_IMDS_Hardening_20251229_015227
ECS on EC2 Covering Gaps in IMDS Hardening
2026-01-13 14:55:32 +01:00
SirBroccoli
5d8a658c6e Merge pull request #237 from HackTricks-wiki/update_A_Survey_of_2024_2025_Open_Source_Supply_Chain_Com_20251229_014719
A Survey of 2024–2025 Open‑Source Supply‑Chain Compromises a...
2026-01-13 14:27:20 +01:00
ryotaromatsui
8ef4c150cf rds-CreateBlueGreenDeployment_passrole privsc 2026-01-12 12:09:28 +09:00
HackTricks News Bot
c86885ebe6 Add content from: Holiday Hack Challenge 2025 (Act 1) - Spare Key 2026-01-06 12:50:55 +00:00
HackTricks News Bot
f9b181a878 Add content from: Holiday Hack Challenge 2025: Blob Storage (Storage Secrets) 2026-01-06 12:45:55 +00:00