mirror of
https://github.com/HackTricks-wiki/hacktricks-cloud.git
synced 2025-12-28 21:53:15 -08:00
894 B
894 B
AWS - RDS Persistence
{{#include ../../../banners/hacktricks-training.md}}
RDS
For more information check:
{{#ref}} ../aws-services/aws-relational-database-rds-enum.md {{#endref}}
Make instance publicly accessible: rds:ModifyDBInstance
An attacker with this permission can modify an existing RDS instance to enable public accessibility.
aws rds modify-db-instance --db-instance-identifier target-instance --publicly-accessible --apply-immediately
Create an admin user inside the DB
An attacker could just create a user inside the DB so even if the master users password is modified he doesn't lose the access to the database.
Make snapshot public
aws rds modify-db-snapshot-attribute --db-snapshot-identifier <snapshot-name> --attribute-name restore --values-to-add all
{{#include ../../../banners/hacktricks-training.md}}