Beginner Friendly
![]()
Plunder Public RDS Snapshots
This foundations-level lab shows the danger of publicly shared Amazon RDS snapshots and how an attacker can exploit them. Starting from only an AWS account ID, you discover a public PostgreSQL snapshot, restore it in your own account, reset the master password, and connect to extract sensitive customer data.
Overview
This foundations-level lab shows the danger of publicly shared Amazon RDS snapshots and how an attacker can exploit them. Starting from only an AWS account ID, you discover a public PostgreSQL snapshot, restore it in your own account, reset the master password, and connect to extract sensitive customer data.
Scenario
Huge Logistics engages your team for an external review of their AWS cloud infrastructure, providing only their account ID. Your task is to uncover exposed resources and demonstrate the real risk they pose.
Lab prerequisites
- Basic Linux command line knowledge
- An AWS account for restoring the snapshot
- AWS CLI configured for your own account
Learning outcomes
- Enumerate public RDS snapshots across regions with the AWS CLI
- Restore a public RDS snapshot into your own account using the RDS console
- Reset the master database password on a restored instance via Modify with Apply immediately
- Set up EC2 connectivity and network access to reach the restored database
- Connect with the PostgreSQL client and enumerate databases, tables, and rows
- Extract PII including credentials and credit card data from the exposed database
- Understand remediation, least privilege, and CloudWatch/CloudTrail detection for snapshot sharing
Real-world context
Research from the Mitiga team found hundreds of RDS snapshots left consistently public within a single month, exposing sensitive databases. Attackers can restore these snapshots into their own accounts and mine them for PII, fueling ransomware, extortion, and other abuse.
Cloud Security Training To Protect Your Business
Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.
We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!