SageMaker runs notebooks, training jobs, and inference endpoints, each attached to an execution role with access to the training data in S3. Two things are worth taking: the data and models, and the execution role. A principal with sagemaker:CreatePresignedNotebookInstanceUrl opens a shell in a running notebook and reads its role credentials from the metadata service, which is the same PassRole escalation documented under identity.
Opening a notebook you can reach#
aws sagemaker list-notebook-instances
aws sagemaker create-presigned-notebook-instance-url --notebook-instance-name <nb>
# open the URL, drop to a terminal, then read the attached role from IMDS
Reading data and models#
aws sagemaker list-training-jobs
aws sagemaker describe-training-job --training-job-name <j> \
--query 'InputDataConfig[].DataSource.S3DataSource.S3Uri' # training data in S3
aws sagemaker list-models ; aws sagemaker describe-model --model-name <m>
Exploitation notes#
- The notebook's execution role is usually broad (full S3, sometimes more); stealing it from IMDS turns data access into account movement.
- Training-job and model definitions point straight at the S3 buckets holding the data, which you then read with the role you just took.
- Creating a new notebook with a passed privileged role is the louder
PassRolevariant when you cannot reach an existing one.
Tools#
- AWS CLI (
sagemaker create-presigned-notebook-instance-url,describe-training-job). - Pacu (
sagemaker__*): enumerate notebooks, jobs, and models.