Storage

GCP keeps bulk data in Cloud Storage buckets, in the persistent disks behind Compute Engine, and in Filestore NFS shares. Each is reached differently: buckets by a global name plus IAM or legacy ACLs, disks by snapshotting and re-attaching them, and Filestore by mounting the share from inside the VPC. The work is finding the store you can reach and pulling the credentials, keys, and databases inside.

What folds in here#

  • Cloud Storage: enumerating public and misconfigured buckets and abusing bucket IAM and ACLs.
  • Disk snapshots: copying a persistent disk and re-attaching it to read another instance's contents.
  • Filestore: mounting NFS shares exposed within the VPC.

HMAC keys that grant S3-interop access to Cloud Storage are a credential and live under credentials.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more