Storage Gateway bridges on-premises hosts to AWS storage: file gateways expose S3 buckets as NFS or SMB shares, and volume gateways present EBS-backed iSCSI volumes. The gateway holds standing access to the backing S3 and EBS, so reaching a gateway's share, or the control-plane configuration of the gateway itself, is an indirect route to the cloud storage behind it.
Enumerating gateways and shares#
aws storagegateway list-gateways --query 'Gateways[].[GatewayId,GatewayType]'
aws storagegateway list-file-shares --query 'FileShareInfoList[].FileShareARN'
aws storagegateway describe-nfs-file-shares --file-share-arn-list <arn> \
--query 'NFSFileShareInfoList[].[LocationARN,ClientList,Squash]'
aws storagegateway list-volumes
The LocationARN on a file share names the S3 bucket it fronts; the ClientList and squash settings tell you who may mount it.
Reaching the data#
# mount an NFS file gateway share exposed to a reachable CIDR
sudo mount -t nfs <gateway-ip>:/<bucket> /mnt/gw
Exploitation notes#
- A file gateway gives NFS/SMB access to the S3 bucket behind it without S3 API permissions, bypassing bucket-policy controls that assume API access.
- Volume gateway iSCSI targets with no CHAP, or weak CHAP, are mountable by anyone who can reach the gateway's network interface.
- Gateway control-plane access (
storagegateway:*) lets you create a new share over an existing bucket, a quieter read path than touching S3 directly.
Tools#
- AWS CLI (
storagegateway list-/describe-*): enumerate gateways, shares, and their backing locations. - mount.nfs / iscsiadm: mount the exposed shares and volumes.