Serverless

A serverless component runs with a role and holds configuration that frequently carries secrets, so reaching one is reaching its role and its config. Lambda is the center of gravity: a function runs under an execution role, its environment variables often hold credentials, and its code is attacker-replaceable. Around it, API Gateway fronts functions and other AWS services, Function URLs expose them directly, and Step Functions and EventBridge orchestrate privileged actions under their own roles.

What folds in here#

  • Execution role: stealing a Lambda function's role credentials from the runtime.
  • Code and layers: reading source and layers for secrets, and overwriting them to run under the role.
  • API Gateway: resource-policy exposure, authorizer bypass, and the integration role.
  • Function URL: a Lambda Function URL with lax auth, invoked directly over HTTPS.
  • Step Functions: state machines and their execution role.
  • EventBridge: rules, buses, and targets fired under a privileged role.

Creating or updating a function to assume a more powerful role is the iam:PassRole path and lives under identity; the pages here cover abusing the services themselves.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more