Parameters
The first interesting piece of information we will want to inspect is what is stored under "Parameters". Available parameters are defined in the stacks template, then the values are passed in when using that template to create a new stack. The names and values of these parameters are stored along with the associated stack and show up under the "Parameters" key of the DescribeStacks API call response.
We are hoping to find some sensitive information being passed in to parameters, where we could then use it to gain further access to the environment. If best practices are being followed, then we ideally should not be able to find any sensitive information in the values of the parameters for a stack, but we have found that best practices ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access