Skip to content

Document live-validated AWS data-access techniques - #379

Merged
carlospolop merged 6 commits into
masterfrom
codex/aws-appstream-streaming-url-20260908
Sep 8, 2026
Merged

Document live-validated AWS data-access techniques#379
carlospolop merged 6 commits into
masterfrom
codex/aws-appstream-streaming-url-20260908

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

Summary

Documents only techniques reproduced in disposable AWS scenarios with exact constrained permissions. Content follows the existing per-service hierarchy and includes commands, prerequisites, no-list discovery fallbacks, limitations, and cleanup evidence.

Validated techniques include AppStream home-folder access through CreateStreamingURL; AppSync API-key theft with real GraphQL data retrieval; AppConfig, Batch, CloudFormation, Glue, Image Builder, Managed Flink, EMR Serverless, EventBridge Pipes/rules/Scheduler, SageMaker, SSM, Step Functions, Auto Scaling, and Elastic Beanstalk configuration disclosures.

Elastic Beanstalk is documented only as the exact tested multi-permission combination; its describe action alone was insufficient. WorkMail and unvalidated EUC candidates are not promoted.

Validation

  • Every documented disclosure recovered a unique random synthetic sentinel.
  • AppSync and AppStream were validated end to end against the data plane.
  • All disposable live resources were deleted; only AWS-retained INACTIVE Batch and TERMINATED EMR historical records remain, with lab tags removed and no active capacity.
  • mdbook build succeeds. Existing warnings originate in unrelated pre-existing pages.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Added a second tested batch in e63182498, following the existing per-service structure:

  • AppConfig Data deployed configuration retrieval
  • AgentCore workload-token/API-key credential chain with its exact Secrets Manager dependency
  • Amazon Connect federation sessions
  • Amazon Q in Connect document download URLs
  • CodePipeline custom-action artifact credentials
  • Deadline queue-role credentials
  • IoT Wireless Sidewalk private keys/certificates
  • Lex V2 bot exports
  • S3 Express and S3 Access Grants credential brokers

Every section includes a no-list fallback, exact tested impact, external-account negative control, and cleanup result. The earlier principal/account validation techniques remain explicitly classified as expected post-exploitation reconnaissance, not vulnerabilities or zero-days.

@carlospolop

Copy link
Copy Markdown
Collaborator Author

Added another live-validated service page in b0227d962: profile:SearchProfiles in Amazon Connect Customer Profiles. A session restricted to that single action returned the full canary PII profile; the service-authorized foreign account was bound to its own account and received domain-not-found. The disposable profile/domain were deleted and verified absent.

@carlospolop
carlospolop merged commit 4c0703d into master Sep 8, 2026
@carlospolop
carlospolop deleted the codex/aws-appstream-streaming-url-20260908 branch September 8, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant