Spanner

Cloud Spanner is a globally distributed relational database reached through IAM. A principal holding spanner.databases.read (or roles/spanner.databaseReader) opens a session and queries any table in the database, so the attack is simply enumerating the instances and databases a token can reach and reading them.

Reading a database#

bash
gcloud spanner instances list
gcloud spanner databases list --instance <inst>
gcloud spanner databases execute-sql <db> --instance <inst> \
  --sql='SELECT * FROM Users LIMIT 1000'

Exploitation notes#

  • spanner.databases.beginOrRollbackReadWriteTransaction and related write permissions let you tamper with rows where the role is broad.
  • Spanner has no public network surface, so access is purely the IAM binding on your principal or an impersonated service account; chase the binding rather than the network.

Tools#

  • gcloud (spanner databases execute-sql).
  • Spanner client libraries for scripted session reads.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more