Cognito

Amazon Cognito is the consumer identity service behind many web and mobile apps, and it bridges application users to real IAM credentials. That bridge is the attack surface: a misconfigured identity pool hands AWS credentials to anonymous callers, and an open user pool lets anyone enroll.

Pages#

  • Identity pool: exchanging an unauthenticated or guest identity for the pool's IAM role credentials.
  • User pool: open self-signup and writable attributes to gain or elevate access.
  • Token claims: abusing ID and access token claims to assume a more privileged identity.

The fastest unauthenticated check is the identity-pool flow: aws cognito-identity get-id for a pool id, then get-credentials-for-identity, which hands back IAM credentials when the pool grants an unauthenticated role (see identity pool).

Tools#

  • cognito-scanner (pip install cognito-scanner): unwanted account creation, the account-existence oracle, and identity-pool credential escalation in one scanner.
  • AWS CLI (cognito-identity, cognito-idp): the raw get-id / get-credentials-for-identity and sign-up / initiate-auth flows.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more