mirror of
https://github.com/swisskyrepo/PayloadsAllTheThings.git
synced 2024-12-12 14:22:47 +00:00
Merge pull request #663 from cfpadok/develop
feat: add cognito-scanner tool for AWS pentest
This commit is contained in:
commit
103f41898b
1 changed files with 11 additions and 0 deletions
|
@ -197,6 +197,17 @@
|
|||
find_admins: Look at IAM policies to identify admin users and roles, or principals with specific privileges
|
||||
```
|
||||
|
||||
* [Cognito Scanner](https://github.com/padok-team/cognito-scanner) - A CLI tool for executing attacks on cognito such as *Unwanted account creation*, *Account Oracle* and *Identity Pool escalation*.
|
||||
```bash
|
||||
# Installation
|
||||
$ pip install cognito-scanner
|
||||
# Usage
|
||||
$ cognito-scanner --help
|
||||
# Get information about how to use the unwanted account creation script
|
||||
$ cogntio-scanner account-creation --help
|
||||
# For more details go to https://github.com/padok-team/cognito-scanner
|
||||
```
|
||||
|
||||
* [dufflebag](https://labs.bishopfox.com/dufflebag) - Find secrets that are accidentally exposed via Amazon EBS's "public" mode
|
||||
* [NetSPI/AWS Consoler](https://github.com/NetSPI/aws_consoler) - Convert AWS Credentials into a console access
|
||||
|
||||
|
|
Loading…
Reference in a new issue