Athena

Athena runs SQL over data in S3 through the Glue Data Catalog. A principal with Athena and the underlying S3 read permissions queries any table the catalog knows about, which is often broader than the buckets they were meant to see. Where a table is not catalogued, CREATE EXTERNAL TABLE points Athena at an arbitrary S3 location and reads it directly.

Querying#

bash
aws athena start-query-execution \
  --query-string 'SELECT * FROM logs.access LIMIT 100' \
  --result-configuration OutputLocation=s3://<reachable-bucket>/out/
aws athena get-query-results --query-execution-id <id>

Reaching uncatalogued data#

sql
CREATE EXTERNAL TABLE loot (line string)
LOCATION 's3://<target-bucket>/path/';
SELECT * FROM loot;

Exploitation notes#

  • Athena's reach is the union of the catalog and the caller's S3 permissions; a broad s3:GetObject plus Athena reads data across many buckets through one interface.
  • Query results land in the configured output bucket, so a readable output location is itself an exfiltration channel.
  • Workgroup settings can force an output location, which is worth reading before assuming where results go.

Tools#

  • AWS CLI (athena start-query-execution, get-query-results).
  • awswrangler: scripted Athena queries and result retrieval.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more