intro to AWS PENTESTING (with Pacu)

Cybr July 20, 2023
Video Thumbnail
Cybr Logo

Cybr

@cybrcom

About

Welcome to Cybr's official YouTube channel! Your Go-To Resource for AWS Cloud Security Training 🔒, Hands-on AWS Security Labs 🛠️, and AWS Security Tutorials. Our in-depth tutorials, real-world scenario walkthroughs, and expert insights into AWS security best practices empower you to secure your cloud environments effectively. Join our community of over 70,000 learners 🌐 to master AWS cloud security together! Subscribe now 🔔 and visit our website at https://cybr.com/ to access exclusive resources and stay updated with the latest in AWS security.

Video Description

In this video, you’re going to learn how to ethically hack AWS cloud environments that you have explicit permissions for so that you can find exploitable vulnerabilities in your own AWS accounts or for your clients as a pentester, before the threat actors do. I’m going to show you step-by-step how to use an open-source tool called Pacu which is used for AWS pentesting and ethical offensive security so that you can follow along with me. Policy shown in the video for you to copy/paste: { "Version": "2012-10-17", "Statement": [ { "Sid": "VisualEditor1", "Effect": "Allow", "Action": "s3:*", "Resource": "arn:aws:s3:::cybr-pacu-lab-example" }, { "Sid": "Statement1", "Effect": "Allow", "Action": [ "iam:Get*", "iam:List*", "iam:Put*", "iam:AttachRolePolicy", "iam:SimulateCustomPolicy", "iam:SimulatePrincipalPolicy" ], "Resource": "*" } ] } 💬 Chat with me Discord: https://cybr.com/discord Website: https://cybr.com LinkedIn: https://www.linkedin.com/in/christophelimpalair/ Twitter: https://twitter.com/christophelimp 🔗 Links mentioned in the video: - Pacu: https://github.com/RhinoSecurityLabs/pacu - AWS: https://aws.amazon.com/ - 🧪 Cybr Hands-On Labs: https://cybr.com/labs 🎓 Courses - Introduction to AWS Security: https://cybr.com/courses/introduction-to-aws-security/ - Injection Attacks The Free Guide: https://cybr.com/courses/injection-attacks-the-free-guide/ 🚨 Disclaimer This video is strictly for educational purposes and to teach you how you can detect and mitigate this threat from your or your employer's AWS enviroments. Learning about ethical hacking and penetration testing is an important way of protecting ourselves against threat actors. Also, not all pentesting actions are allowed on the AWS platform as per the AWS ToS, however, what we demonstrate in this video is allowed and perfectly fine. For more details, refer to this page: https://aws.amazon.com/security/penetration-testing/ ⏱ Timestampts: 00:00 - 00:13 - Introduction 00:14 - 00:31 - Disclaimer 00:32 - 00:46 - About Pacu 00:47 - 01:00 - AWS account setup 01:01 - 01:39 - Installing Pacu 01:40 - 02:16 - Running Pacu 02:17 - 02:46 - About access keys 02:47 - 03:09 - Use test environments! 03:10 - 03:30 - Creating an AWS user 03:31 - 04:14 - Creating user policies 04:15 - 04:29 - Adding the policy to our user 04:30 - 05:08 - Creating our access key 05:09 - 05:45 - Adding the keys to Pacu 05:46 - 06:24 - Pacu modules 06:25 - 06:37 - run iam__enum_permissions 06:38 - 07:00 - whoami 07:01 - 08:04 - run iam__privesc_scan 08:05 - 08:21 - Confirming admin permissions via Pacu 08:22 - 08:34 - Confirming admin permissions via console 08:35 - 09:36 - Detailed explanation of the vulnerability 09:37 - 09:53 - Explanation of how Pacu pulled this off 09:54 - 10:18 - Learning IAM is important! 10:19 - 10:34 - Learn more about AWS security 10:35 - 10:40 - More AWS Security courses coming! 10:41 - 11:00 - Cybr Labs are coming! 11:01 - 11:05 - Outro #awssecurity #cloudsecurity #cloudpentesting #pentesting #pentester #securityassessment #opensource #cybersecurity #aws

You May Also Like

Upgrade Your Gear Today

AI-recommended products based on this video

Loading...
Anker Power Bank(PowerCore 10K),Compact Travel-Ready 10,000mAh Battery Pack with PowerIQ Charging Technology,5V/3A High-Speed Charging for iPhone,iPad,and More (USB-C Input and Output(Black),1pack) ClimatePartner certified

Anker Power Bank(PowerCore 10K),Compact Travel-Ready 10,000mAh Battery Pack with PowerIQ Charging Technology,5V/3A High-Speed Charging for iPhone,iPad,and More (USB-C Input and Output(Black),1pack) ClimatePartner certified

(109,961)
$17.99$17.81
FREE delivery Fri, Aug 8 on $35 of items shipped by Amazon
10K+ bought in past month
Loading...
COOWPS Switch Case for Nintendo Switch and Switch OLED Model, Portable Full Protection Carrying Travel Bag with 18 Game Cards Storage for Switch Console Pro Controller Accessories Black

COOWPS Switch Case for Nintendo Switch and Switch OLED Model, Portable Full Protection Carrying Travel Bag with 18 Game Cards Storage for Switch Console Pro Controller Accessories Black

(2,497)
$24.99$22.99
FREE delivery Mon, Jun 16 on $35 of items shipped by Amazon
800+ bought in past month
Loading...
UGREEN Revodok Pro 210 Docking Station 10 in 1 USB C Dock Dual HDMI 4K@60Hz Single 8K@30Hz 100W PD 5Gbps USB C and USB A Data Ports Gigabit Ethernet, SD/TF Card Reader USB Hub Compatible for HP, Dell

UGREEN Revodok Pro 210 Docking Station 10 in 1 USB C Dock Dual HDMI 4K@60Hz Single 8K@30Hz 100W PD 5Gbps USB C and USB A Data Ports Gigabit Ethernet, SD/TF Card Reader USB Hub Compatible for HP, Dell

(1,701)
39.99
PrimeFREE delivery Saturday, June 14
100+ bought in past month
Loading...
Apple iPad 11-inch: A16 chip, 11-inch Model, Liquid Retina Display, 128GB, Wi-Fi 6, 12MP Front/12MP Back Camera, Touch ID, All-Day Battery Life — Blue EPEAT
Best Seller

Apple iPad 11-inch: A16 chip, 11-inch Model, Liquid Retina Display, 128GB, Wi-Fi 6, 12MP Front/12MP Back Camera, Touch ID, All-Day Battery Life — Blue EPEAT

(10,496)
$279.00$276.21
FREE delivery Fri, Oct 17
10K+ bought in past month
Loading...
Wireless Bluetooth Mouse for Apple iPad iPhone MacBook Android Samsung Tablet Phone Dual-Mode Rechargeable 2.4G Portable Computer Mice for Windows Laptop Notebook PC Mac Desktop USB Receiver (Black)

Wireless Bluetooth Mouse for Apple iPad iPhone MacBook Android Samsung Tablet Phone Dual-Mode Rechargeable 2.4G Portable Computer Mice for Windows Laptop Notebook PC Mac Desktop USB Receiver (Black)

(1,960)
9.99
PrimeFREE delivery Saturday, June 14 on orders shipped by Amazon over $35
500+ bought in past month
Loading...
Apple AirTag 4 Pack. Keep Track of and find Your Keys, Wallet, Luggage, Backpack, and More. Simple one-tap Set up with iPhone or iPad

Apple AirTag 4 Pack. Keep Track of and find Your Keys, Wallet, Luggage, Backpack, and More. Simple one-tap Set up with iPhone or iPad

(33,518)
$64.99$63.04
FREE delivery Sun, Nov 2
10K+ bought in past month
Loading...
Apple AirTag. Keep Track of and find Your Keys, Wallet, Luggage, Backpack, and More. Simple one-tap Set up with iPhone or iPad

Apple AirTag. Keep Track of and find Your Keys, Wallet, Luggage, Backpack, and More. Simple one-tap Set up with iPhone or iPad

(44,035)
$24.99$23.44
FREE delivery Tue, Nov 4 on $35 of items shipped by Amazon
10K+ bought in past month