Direct Connect

Direct Connect is a dedicated link between an on-premises network and AWS, exposed through virtual interfaces (VIFs) that attach to VPCs or to a Direct Connect gateway. A foothold on either side of a VIF reaches the other: a compromised VPC role reads the hybrid routing that leads on-premises, and a compromised on-premises host rides the private VIF into VPC ranges that assume the link is trusted.

bash
aws directconnect describe-connections
aws directconnect describe-virtual-interfaces \
  --query "virtualInterfaces[].[virtualInterfaceId,virtualInterfaceType,vlan,amazonAddress,customerAddress,virtualGatewayId]"
aws directconnect describe-direct-connect-gateways

Exploitation notes#

  • Private VIF address pairs (amazonAddress / customerAddress) reveal the hybrid link's inside ranges to scan from a VPC foothold.
  • Traffic over a private VIF is often implicitly trusted on both sides, so controls that assume an internet boundary do not apply.
  • A Direct Connect gateway can attach the link to multiple VPCs and accounts, widening the blast radius of either side's compromise.

Tools#

  • AWS CLI (directconnect describe-*): link, VIF, and gateway enumeration.
  • Route/VPC analysis (VPC): correlate VIF-advertised ranges with reachable subnets.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more