Open 0xCardinal opened 2 years ago
Privilege Escalation in GCP Service Account-based - https://www.praetorian.com/blog/google-cloud-platform-gcp-service-account-based-privilege-escalation-paths/
SSRF in Google Cloud functions - https://github.com/ine-labs/GCPGoat.
Lateral Movement in Google Cloud Compute Instances - https://github.com/ine-labs/GCPGoat
Misconfigured Google Cloud Storage Bucket Policies - https://github.com/ine-labs/GCPGoat
Saksham -
Sagar -
Ashwin -
Created separate issues for all the misconfigurations
Saksham: Misconfigured cloud storage buckets - https://threatpost.com/google-cloud-buckets-exposed-misconfiguration/159429/
RCE in Google Cloud Deployment Manager - https://portswigger.net/daily-swig/google-awards-uruguayan-researcher-133-337-top-prize-in-cloud-security-competition
SSRF in Google Cloud Monitoring led to metadata exposure - https://nechudav.blogspot.com/2020/11/31k-ssrf-in-google-cloud-monitoring.html
Privilege Escalation in Google Cloud Platform's OS Login - https://about.gitlab.com/blog/2020/02/12/plundering-gcp-escalating-privileges-in-google-cloud-platform/
Misconfigured GCP firewall
Overly permissive permission in GCP IAM