Files
hacktricks-cloud/src/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-clientauthconfig-privesc.md

991 B

GCP - ClientAuthConfig Privesc

{{#include ../../../banners/hacktricks-training.md}}

OAuth ブランドとクライアントの作成

According to the docs、これらが必要な権限です:

  • clientauthconfig.brands.list
  • clientauthconfig.brands.create
  • clientauthconfig.brands.get
  • clientauthconfig.clients.create
  • clientauthconfig.clients.listWithSecrets
  • clientauthconfig.clients.getWithSecret
  • clientauthconfig.clients.delete
  • clientauthconfig.clients.update
OAuth ブランドとクライアントを作成 ```bash # Create a brand gcloud iap oauth-brands list gcloud iap oauth-brands create --application_title=APPLICATION_TITLE --support_email=SUPPORT_EMAIL # Create a client of the brand gcloud iap oauth-clients create projects/PROJECT_NUMBER/brands/BRAND-ID --display_name=NAME ```

{{#include ../../../banners/hacktricks-training.md}}