[CLOUD] Amazon S3 and IAM Services

<aside> 💡 Shadow IT - use of information technology systems, devices, software, applications, and services without explicit IT department approval

</aside>

<aside> 💡 Public Cloud is an easy way for business units to engage in shadow IT.

</aside>

<aside> 💡 Amazon S3 -

<aside> 💡 AWS IAM (Identity and Access Management) :-

Questions âž–

1 - URL Inspection

2, 3 - Enumeration in s3 services

4 - unzipand grep -r command. file contains all passwords/keys

5 - configure and add details (generally, not in a profile yet)

6 - configure and add details in a profile

7 - list the ec2 instances

8 - secretsmanager list-secrets, secretsmanager get-secret-value --secret-id <name>, secretsmanager get-secret-value --secret-id <name> --region <name>

Last one’s a little lengthy but if done slowly and understood then could be done easily