Bucket - HackTheBox Writeup (10.10.10.212)

Posted on Sun, May 2, 2021 Medium Linux Amazon DynamoDB Amazon S3 Pd4Cmd
Medium-difficulty Linux box all about exploiting improperly configured Amazon S3 buckets. Privilege escalation by extracting credentials from DynamoDB and leveraging arbitrary file read through PD4ML, an HTML-to-PDF tool.

Recon

Enumeration

HTTP Enumeration

DynamoDB Enumeration

Exploitation

S3 Directory Traversal

Privilege Escalation

AWS Project

Port 8000

Post-exploitation

Persistence

Resources

  1. https://docs.aws.amazon.com/cli/latest/userguide/cli-services-dynamodb.html