google / gcp_scanner

A comprehensive scanner for Google Cloud
Apache License 2.0
304 stars 95 forks source link

Explore an option of detecting SA's with DWD #306

Open mshudrak opened 8 months ago

mshudrak commented 8 months ago

[Is your feature request related to a problem? Please describe. There are GCP SA with DWD capabilities. It would be nice to identify them.

Describe the solution you'd like GCP SA flag SA with DWD permissions

Additional context https://www.hunters.security/en/blog/delefriend-a-newly-discovered-design-flaw-in-domain-wide-delegation-could-leave-google-workspace-vulnerable-for-takeover)](https://www.hunters.security/en/blog/delefriend-a-newly-discovered-design-flaw-in-domain-wide-delegation-could-leave-google-workspace-vulnerable-for-takeover