VPC

Once you hold an instance or a role inside a VPC, the network layout decides how far you can reach. Peering connections, transit gateways, and routing tables stitch VPCs together (often across accounts), and VPC endpoints expose AWS service access paths. Reading the routing and peering graph with ec2:Describe* shows which internal ranges and accounts are reachable from your foothold.

Reading the reachability graph#

bash
aws ec2 describe-vpc-peering-connections \
  --query "VpcPeeringConnections[].[VpcPeeringConnectionId,RequesterVpcInfo.CidrBlock,AccepterVpcInfo.CidrBlock]"
aws ec2 describe-route-tables \
  --query "RouteTables[].Routes[].[DestinationCidrBlock,GatewayId,VpcPeeringConnectionId,TransitGatewayId]"
aws ec2 describe-transit-gateway-attachments

Endpoints and interface services#

bash
# interface/gateway endpoints reveal which services the VPC can reach privately
aws ec2 describe-vpc-endpoints \
  --query "VpcEndpoints[].[ServiceName,VpcEndpointType,VpcId]"

Exploitation notes#

  • A peering route to another account's CIDR is a cross-account pivot: scan that range from your foothold once a route exists.
  • Transit gateways concentrate reachability; one attachment can expose many VPCs at once.
  • Interface endpoints with permissive endpoint policies let an in-VPC principal reach services the account meant to keep private.

Tools#

  • AWS CLI (ec2 describe-*): the routing and peering graph.
  • ScoutSuite: visualize peering and endpoint exposure.
  • pmapper: cross-account IAM edges that often parallel the network peering.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more