Beginner Friendly red team icon   azure

Abuse Cognito User and Identity Pools

This intermediate lab teaches how permissive Amazon Cognito User Pool and Identity Pool configurations let attackers gain a foothold and then pivot deeper into a cloud environment. Starting from leaked mobile app source code, you obtain unauthenticated and authenticated AWS credentials, then abuse an over-permissive IAM role and a vulnerable Lambda function to move laterally and vertically. A key outcome is understanding how each link in the chain could have been prevented.

Overview

This intermediate lab teaches how permissive Amazon Cognito User Pool and Identity Pool configurations let attackers gain a foothold and then pivot deeper into a cloud environment. Starting from leaked mobile app source code, you obtain unauthenticated and authenticated AWS credentials, then abuse an over-permissive IAM role and a vulnerable Lambda function to move laterally and vertically. A key outcome is understanding how each link in the chain could have been prevented.

Scenario

During an external sweep of Huge Logistics, your team found a public git repository containing the full source code of the company's new Android application. You must review it for vulnerabilities and see how far those breadcrumbs lead into the company's cloud environment.

Lab prerequisites
  • Basic Linux command-line knowledge
  • Familiarity with the AWS CLI
Learning outcomes
  • Extract Cognito Identity Pool IDs and other secrets from leaked application source code
  • Obtain unauthenticated AWS credentials via cognito-identity get-id and get-credentials-for-identity
  • Abuse self sign-up on a Cognito User Pool and confirm accounts to obtain authenticated JWTs
  • Exchange User Pool tokens for higher-privileged Identity Pool IAM credentials
  • Enumerate IAM role policies and discover Lambda access using the AWS CLI
  • Exploit SSRF and arbitrary file read in a Lambda function to steal credentials from /proc/self/environ
  • Pivot with stolen Lambda role credentials to loot S3 buckets containing sensitive documents
Real-world context

Misconfigured Cognito Identity Pools that allow unauthenticated access have exposed thousands of buckets, tables, and Lambda functions in the wild, and a single over-permissive role or unvalidated Lambda input can chain into a full account compromise.

platform mock(1)

Cloud Security Training To Protect Your Business

Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.

We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!