Keyspaces is AWS's Cassandra-compatible database. It is reached either with service-specific credentials (a generated username and password tied to an IAM user) or with SigV4 signing, and a principal holding cassandra:Select reads any table the policy allows. Over-broad grants and recoverable service-specific credentials are the way in.
Connecting and reading#
aws keyspaces list-keyspaces ; aws keyspaces list-tables --keyspace-name <ks>
# cqlsh with service-specific credentials over TLS (port 9142)
cqlsh cassandra.<region>.amazonaws.com 9142 --ssl \
-u <svc-user> -p <svc-pass>
> SELECT * FROM ks.table LIMIT 100;
Exploitation notes#
- Service-specific credentials are generated per IAM user and, once recovered, give direct CQL access independent of further IAM checks.
- A SigV4 plugin for the Cassandra driver lets a holding principal connect without a stored password at all.
- Broad
cassandra:Selectat the service level reads every table in the account's keyspaces.
Tools#
- AWS CLI (
keyspaces list-keyspaces,list-tables). - cqlsh with the SigV4 auth plugin: native CQL access.