Sirviendo Código

Carlos Polop - Vulnerability or feature? - X-OPS 25

9 de diciembre de 2025Ciberseguridadciberseguridadxops

Over the past years, I have conducted extensive research into how attackers can exploit various features of Google Cloud Platform (GCP) and Google Workspace to escalate privileges, maintain persistence, and execute post-exploitation actions. This work has uncovered numerous behaviors that hold significant value for Red Teams. While some of these findings have prompted GCP to implement fixes, others have been acknowledged as inherent features of the platform. Key discoveries include: - Methods to perform critical actions without generating audit logs. - Exploiting environment variables to achieve remote code execution (RCE) on systems and containers that are not intended to be directly accessible. - Techniques for pivoting from Google Cloud Storage buckets to other GCP services and Service Accounts. - Leveraging containers to establish "invisible" persistence mechanisms. Additionally, my research has focused on understanding and exploiting the behaviour of Google’s enterprise tools, such as: - Google Credential Provider for Windows - Google Cloud Directory Sync - Google Password Sync - Admin Directory Sync These tools can be used to pivot and escalate privileges from environments like Windows, Active Directory, and Microsoft Entra ID into Google Workspace, ultimately gaining access to GCP. ------- Síguenos en nuestras redes sociales Web: https://sirviendocodigo.com/ LinkedIn: https://www.linkedin.com/company/sirviendo-codigo/ X: https://twitter.com/sirviendocodigo Instagram: https://www.instagram.com/sirviendo.codigo/ TikTok: https://www.tiktok.com/@sirviendo.codigo #sirviendocodigo

Vídeos relacionados