null-open-security-community / Cloud-Project

8 stars 2 forks source link

Make list of security issue for GCP #2

Open 0xCardinal opened 1 year ago

0xCardinal commented 1 year ago

Saksham: Misconfigured cloud storage buckets - https://threatpost.com/google-cloud-buckets-exposed-misconfiguration/159429/

RCE in Google Cloud Deployment Manager - https://portswigger.net/daily-swig/google-awards-uruguayan-researcher-133-337-top-prize-in-cloud-security-competition

SSRF in Google Cloud Monitoring led to metadata exposure - https://nechudav.blogspot.com/2020/11/31k-ssrf-in-google-cloud-monitoring.html

Privilege Escalation in Google Cloud Platform's OS Login - https://about.gitlab.com/blog/2020/02/12/plundering-gcp-escalating-privileges-in-google-cloud-platform/

Misconfigured GCP firewall

Overly permissive permission in GCP IAM

saksham3022 commented 1 year ago

Privilege Escalation in GCP Service Account-based - https://www.praetorian.com/blog/google-cloud-platform-gcp-service-account-based-privilege-escalation-paths/

SSRF in Google Cloud functions - https://github.com/ine-labs/GCPGoat.

Lateral Movement in Google Cloud Compute Instances - https://github.com/ine-labs/GCPGoat

Misconfigured Google Cloud Storage Bucket Policies - https://github.com/ine-labs/GCPGoat

0xCardinal commented 1 year ago

Saksham -

  1. SSRF in Google Cloud functions
  2. Lateral Movement in Google Cloud Compute Instances
  3. Misconfigured Google Cloud Storage Bucket Policies

Sagar -

  1. Misconfigured GCP firewall
  2. Compute/RDS - Ashwin will update.

Ashwin -

  1. Overly permissive permission in GCP IAM
  2. Privilege Escalation in GCP Service Account-based
  3. GCP Metadata Service
0xCardinal commented 1 year ago

Created separate issues for all the misconfigurations