April 2019
Intermediate to advanced
508 pages
11h 57m
English
With the correct RDS permissions, we can potentially gain full access to any RDS database instance in our target account as the administrator user, which would grant us full access to the data stored within.
This attack process can be done manually, or with the rds__explore_snapshots Pacu module. The goal is to abuse RDS database instance backups to create a new copy of the existing databases with our own private access. If we gained access to RDS and there was a single instance and no backups, the process would entail the following steps:
Read now
Unlock full access