Carlos Polop - Vulnerability or feature? - X-OPS 25
Over the past years, I have conducted extensive research into how attackers can exploit various features of Google Cloud Platform (GCP) and Google Workspace to escalate privileges, maintain persistence, and execute post-exploitation actions. This work has uncovered numerous behaviors that hold significant value for Red Teams. While some of these findings have prompted GCP to implement fixes, others have been acknowledged as inherent features of the platform. Key discoveries include: - Methods to perform critical actions without generating audit logs. - Exploiting environment variables to achieve remote code execution (RCE) on systems and containers that are not intended to be directly accessible. - Techniques for pivoting from Google Cloud Storage buckets to other GCP services and Service Accounts. - Leveraging containers to establish "invisible" persistence mechanisms. Additionally, my research has focused on understanding and exploiting the behaviour of Google’s enterprise tools, such as: - Google Credential Provider for Windows - Google Cloud Directory Sync - Google Password Sync - Admin Directory Sync These tools can be used to pivot and escalate privileges from environments like Windows, Active Directory, and Microsoft Entra ID into Google Workspace, ultimately gaining access to GCP. ------- Síguenos en nuestras redes sociales Web: https://sirviendocodigo.com/ LinkedIn: https://www.linkedin.com/company/sirviendo-codigo/ X: https://twitter.com/sirviendocodigo Instagram: https://www.instagram.com/sirviendo.codigo/ TikTok: https://www.tiktok.com/@sirviendo.codigo #sirviendocodigo
Vídeos relacionados

Wilmer Edgardo Martinez - Las máscaras de datos con SQL Server, ¿Cómo lo ves desde Power BI?

Andres Biarge - Los 3 pasos clave para un Gobierno efectivo de Power Platform

