Amazon Cognito is the consumer identity service behind many web and mobile apps, and it bridges application users to real IAM credentials. That bridge is the attack surface: a misconfigured identity pool hands AWS credentials to anonymous callers, and an open user pool lets anyone enroll.
Pages#
- Identity pool: exchanging an unauthenticated or guest identity for the pool's IAM role credentials.
- User pool: open self-signup and writable attributes to gain or elevate access.
- Token claims: abusing ID and access token claims to assume a more privileged identity.
The fastest unauthenticated check is the identity-pool flow: aws cognito-identity get-id for a pool id, then get-credentials-for-identity, which hands back IAM credentials when the pool grants an unauthenticated role (see identity pool).
Tools#
- cognito-scanner (
pip install cognito-scanner): unwanted account creation, the account-existence oracle, and identity-pool credential escalation in one scanner. - AWS CLI (
cognito-identity,cognito-idp): the rawget-id/get-credentials-for-identityandsign-up/initiate-authflows.