Hacking in the Cloud - iam_privesc_by_rollback

Hacking in the Cloud - iam_privesc_by_rollback

in

This is the second scenario in the CloudGoat series, and it is the simplest one at the time of writing. We start off as a high-privileged user who can change their defualt policy version. One of the versions of this user’s managed policy allows for performing any action on any resource. The user can therefore change their default version to this policy version and obtain Administrator access.


00:00 - Video Context
00:52 - Enumerating user’s permissions
06:37 - Changing policy’s default permissions
09:45 - Getting AdministratorAccess