Neptune is AWS's managed graph database, reached over its cluster endpoint inside a VPC. Where IAM database authentication is disabled, any principal that can reach the endpoint queries it with no further auth; where it is enabled, a SigV4-signed request from a holding principal is accepted. The graph often encodes identity and relationship data that is valuable in its own right.
Finding and querying#
aws neptune describe-db-clusters \
--query 'DBClusters[].[DBClusterIdentifier,Endpoint,Port,IAMDatabaseAuthenticationEnabled]'
# Gremlin over HTTP against a reachable endpoint (IAM auth disabled)
curl -s https://<endpoint>:8182/gremlin \
-d '{"gremlin":"g.V().limit(100)"}'
Exploitation notes#
- Neptune lives in a VPC, so this is reached from a compromised EC2 host or a pivot, not the internet.
- With IAM auth off, endpoint reachability is the only control; with it on, a signed request from a permitted principal still works.
- Both Gremlin and SPARQL endpoints are exposed depending on the engine, so try both.
Tools#
- AWS CLI (
neptune describe-db-clusters). - curl / gremlin-console / SPARQL clients: native query access.