pacu icon indicating copy to clipboard operation
pacu copied to clipboard

iam__privesc_scan - unexpected exit on method CodeStarCreateProjectFromTemplate

Open ertygiq opened this issue 10 months ago • 1 comments

I'm running iam__privesc_scan After few attempts with different methods, the module tries 'CodeStarCreateProjectFromTemplate' method and exits with the following message in the output:

...
[iam__privesc_scan]   Method failed. Trying next potential method...
[iam__privesc_scan] No auto-exploitation setup for CodeStarCreateProjectFromTemplate, visit the blog on this privilege escalation method for a standalone exploitation script: https://rhinosecuritylabs.com/aws/escalating-aws-iam-privileges-undocumented-codestar-api

[iam__privesc_scan] iam__privesc_scan completed.

[iam__privesc_scan] MODULE SUMMARY:

  Privilege escalation was successful

Expected behavior: the module will continue to try other methods.

ertygiq avatar Apr 09 '24 23:04 ertygiq

I think the privesc methods just were not returning False on fail. Could you give this branch a try: https://github.com/RhinoSecurityLabs/pacu/tree/fix/415 and see if that fixes the issue?

DaveYesland avatar May 17 '24 18:05 DaveYesland