Posts under this project (4)
Part 1: Overview of AWS CodeConnections (Escalating Privileges via AWS CodeConnections)
AWS CodeConnections (formally called CodeStar Connections) is a feature in AWS which allows AWS resources such as AWS CodePipeline to connect to external code repositories. This is often...
by Thomas Preece Read more...Part 2: AWS CodeBuild (Escalating Privileges via AWS CodeConnections)
In this post we show how to use a malicious Docker Image to monitor network traffic within CodeBuild and find undocumented AWS API calls. From this we'll find...
by Thomas Preece Read more...Part 3: AWS CodePipeline (Escalating Privileges via AWS CodeConnections)
According to AWS, CodePipeline automates the build, test, and deploy phases of your release process each time a code change occurs.
by Thomas Preece Read more...Part 4: AWS SageMaker AI, SageMaker Unified Studio & App Runner (Escalating Privileges via AWS CodeConnections)
SageMaker Unified Studio is a suite of tools from AWS that are combined to provide a single data and AI development environment. This service provides it's own dedicated...
by Thomas Preece Read more...This series of blog posts aims to answer the question, can we significantly escalate our privileges via the source code provider permissions granted to AWS if we can compromise a single AWS account or single AWS service such as CodePipeline.