Instance Connect

EC2 Instance Connect pushes a short-lived SSH public key to a running instance's metadata for a 60-second login window. ec2-instance-connect:SendSSHPublicKey against an instance that carries a privileged instance profile gets you a shell on it, where IMDS hands out the profile role's credentials.

Push a key and connect#

bash
aws ec2-instance-connect send-ssh-public-key \
  --instance-id <id> --instance-os-user ec2-user \
  --ssh-public-key "$(cat ~/.ssh/id_ed25519.pub)"
ssh ec2-user@<instance-ip>        # within 60s of the push
# on the box, read the profile role creds from IMDS

Exploitation notes#

  • You need network reachability to the instance (public IP or a route in), plus SendSSHPublicKey and the instance running the Instance Connect agent.
  • Once on the host, retrieval of the role credentials follows instance metadata.
  • The pushed key is ephemeral, which keeps the footprint small compared with editing authorized_keys.

Tools#

  • AWS CLI (ec2-instance-connect send-ssh-public-key).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more