#NahamCon2022EU: Hunting for Amazon Cognito Security Misconfigurations by@yassineaboukir — Transcript
Full transcript
- 0:00hello everyone uh
- 0:03thank you so much for tuning in uh we're
- 0:05going to talk about ewe's Cognito as a
- 0:10solution for authentication and
- 0:12authorization then we're going to mainly
- 0:14go over a few common security
- 0:16misconfigurations that can affect its
- 0:18implementation
- 0:19I've chosen this topic because I've seen
- 0:22how easier it is to misconfigure it as
- 0:24well as the fact that a lot of people
- 0:26especially about hunters I think it's
- 0:29difficult to test whereas it really is
- 0:31not as long as you just understands how
- 0:34it works
- 0:36before we get into it let me introduce
- 0:38myself for those who do not know me uh
- 0:41my name is Yasin abukir I'm originally
- 0:43from Morocco based in France uh I've got
- 0:47a decade of experience in application
- 0:49security Consulting I work with
- 0:52companies that provide them with
- 0:53painters security assessments Services
- 0:56uh and that in similar regards I this
- 1:00year I joined hack one paint this
- 1:02program and I've been working with their
- 1:03clients as well so I've been doing
- 1:05background names for a very long time
- 1:07probably since late 2013 early 2014 to
- 1:11be accurate I mainly hack on hack one
- 1:14platform where I'm currently ranking in
- 1:16the top 20.
- 1:17so this year I've been fortunate I
- 1:20earned the most valuable hacker the
- 1:22image title and the first place at a
- 1:25live hacking event that took place in
- 1:27Denver
- 1:28as you can see in the picture in the
- 1:30right that's me holding the Bell looking
- 1:32like a UFC fighter there
- 1:35uh from 2017 to 2019 I had the chance to
- 1:39work for hacker one as a part of the
- 1:41triage team it was a great experience
- 1:43and I also love traveling and been doing
- 1:46it for a couple of years now as a
- 1:48digital Nomad just hacking from
- 1:50different places
- 1:52oh yeah that's it so let's get into it
- 1:54introduction to ew's Cognito uh if
- 1:57you've got any developer background you
- 2:00know that user authentication and
- 2:01authorization can be quite challenging
- 2:04when you're building a web and mobile
- 2:06app
- 2:06so the challenges like include handling
- 2:09just user data passwords token based
- 2:12authentication and managing permissions
- 2:15uh scalability Federation
- 2:18Etc so it is pretty easy to mix things
- 2:21up especially with on indications which
- 2:23is quite sensitive
- 2:25so Amazon Cognito offers like a scalable
- 2:29and complete solution to add a sign up
- 2:32and assigning features to your
- 2:34application it provides identity
- 2:37Federation makes it and makes just
- 2:40implementing security easier as long as
- 2:43you're just careful with how you're
- 2:45configuring it
- 2:47so uh Cognito allows not only managing
- 2:51authentication but it also provides a
- 2:54way to manage authorization user
- 2:57permissions which are usually time and
- 3:00resources consuming to properly build so
- 3:04when we talk about Cognito there are two
- 3:07main components on say concepts to
- 3:10distinguish
- 3:11first one is the user poll so when
- 3:14you're creating
- 3:15um when you're setting up cognitively
- 3:17you create the user pool and the user
- 3:20pool here allows authentication
- 3:21basically sign in and sign up and then
- 3:25we have the identity pool uh it refers
- 3:29it is used for authorization to allow
- 3:32users to use various AWS resources such
- 3:36as Amazon dynamodb Amazon S3 API Gateway
- 3:41Etc so these are the two main Concepts
- 3:44to remember
- 3:46this is a the architectural diagram that
- 3:50reflects a high level authentication and
- 3:52authorization flow uh so basically you
- 3:56have the user uh that authenticates to
- 3:59their account uh so when they're
- 4:02authenticated to their account they're
- 4:04checked against a user pool here and
- 4:07then the user poll will generate and
- 4:09return three GWT tokens uh ID access
- 4:14refresh token the ID token the access
- 4:17token and the refresh token and then the
- 4:21ID token is passed to the identity pool
- 4:24the user then will receive a temporary
- 4:27credentials with permissions that are
- 4:30based on the EM role that was mapped to
- 4:34the group that the user belongs to so
- 4:36the user can then make calls to various
- 4:38ew Services based on their role
- 4:41permissions assigned to their
- 4:43credentials in this case they can't
- 4:45access the dynamodp with the AWS
- 4:48credentials as you can see there
- 4:51uh all right how the question is how you
- 4:55can tell uh if an application is
- 4:57actually using Amazon Cognito so uh when
- 5:01you're doing a testing it's pretty easy
- 5:03like if you're using the the web proxy
- 5:07for example burp Suite you can just see
- 5:09that there are some API calls to Cognito
- 5:12endpoint here
- 5:14there are two different ones the yellow
- 5:16one is the request the is being made or
- 5:20being sent at user pull as we mentioned
- 5:22before when you're authenticating to
- 5:24your account the green one is sent after
- 5:27authentication to Identity pull a to
- 5:31exchange basically to exchange the ID
- 5:32token into a temporary WS credential as
- 5:36we previews previously mentioned in the
- 5:38diagram earlier so I've been personally
- 5:41playing with ews cognitive and exploring
- 5:43very security configurations in the
- 5:45console and I've concluded that it's
- 5:47quite far easier to mix things up as
- 5:49there are too many features and security
- 5:51configurations that could confuse any
- 5:54developer uh I've also came across a lot
- 5:59of these security misconfigurations both
- 6:02while doing back downies and penetration
- 6:04distance so they're actually very common
- 6:05to find
- 6:07oh okay we're gonna start with the first
- 6:09one uh the very first security
- 6:11misconfiguration is when the temporary
- 6:13AWS credentials are over permissive
- 6:17liberal credentials in a sense that the
- 6:21unintentionally allow access to or net
- 6:24to net they give you access to or
- 6:26manipulate other sensitive ewas services
- 6:31this is especially bad when
- 6:34unauthenticated roles are enabled as
- 6:36anyone without having an access to an
- 6:39account could generate these temporary
- 6:41credentials and just gain unauthorized
- 6:44access to these ew services
- 6:47so assuming we're not authenticated and
- 6:49we do not have access to an account
- 6:52there is a huge chance unauthenticated
- 6:55roles are enabled in the console by the
- 6:58developer so we basically just need to
- 7:00find the identity poll ID and AWS region
- 7:04which most
- 7:06likely are like over 80 percent of the
- 7:09time they're just hard coded somewhere
- 7:10in the source code or in a JS file
- 7:13so this is the example here as you can
- 7:15see below of a tech Bounty Target I was
- 7:17hacking on and I was able to find these
- 7:19pieces of information in a JS file that
- 7:22was being loaded by the app so it is
- 7:25mainly the user polidy the client ID the
- 7:29region and the identity pool ID the
- 7:32latter is what we're actually interested
- 7:33in and
- 7:36so you can just use burp Suite to search
- 7:38for the following keywords in order to
- 7:40find the identity pool ID but remember
- 7:44that the disclosure of this ID
- 7:47is not necessarily an issue or a
- 7:49security misconfiguration as long as the
- 7:51backend is properly configured right
- 7:55okay so actually I find the identity ID
- 7:58in the JS file or in the source code you
- 8:02can use or download the ews client which
- 8:05is widely used and just configure it
- 8:07then you can simply run the command the
- 8:10AWS command as you can see there in the
- 8:12green with the replacing the pull
- 8:16replacing the pull identity ID and the
- 8:18region so after you execute the command
- 8:21it will generate an identity ID this is
- 8:24different from the pull identity ID just
- 8:26the same name so it will generate an
- 8:28identity ID that you can see in a
- 8:31screenshot there
- 8:32and then you'll just have to copy the
- 8:35identity ID that was generated and
- 8:38execute the next command here in the
- 8:40green and this will generate temporary
- 8:43AWS credentials for you so this will
- 8:46generate an access key ID the secret key
- 8:49and decision token
- 8:51now we will check if these credentials
- 8:55the generated credentials for this an
- 8:57authenticator will have any liberal
- 8:59permissions that would allow further
- 9:02access to the app or to the their AWS
- 9:05Services there are mainly two tools that
- 9:08I recommend and I use the first one is
- 9:11enumerate aeon this is pretty this is
- 9:14this one is pretty easy to use and quite
- 9:16minimalistic as it allows enumerating
- 9:18these permissions uh there is also a
- 9:21comprehensive one called Scout Suite
- 9:23this one is more comprehensive and does
- 9:25the same thing uh you can check their
- 9:27GitHub represent rate on how you can
- 9:29configure it but in this screenshot I
- 9:32mainly used enumerate em and managed to
- 9:35enumerate some permissions uh associated
- 9:38with the credential that we generated
- 9:40but in this screenshot nothing really
- 9:43was interesting I don't have any
- 9:45screenshots so
- 9:47uh
- 9:48like sensitive services that I've had
- 9:50successfully unfortunately but as you
- 9:52can see the the idea is the same we
- 9:55enumerated some permissions like the git
- 9:57color identity this one is now
- 9:59interesting and the Dynamo described in
- 10:01Plants both are not interesting they
- 10:03just return some details first one
- 10:05details about the user or role that is
- 10:07being used and the second one is just
- 10:09the returns details about the endpoints
- 10:12of the current AWS region so
- 10:15uh so yeah unfortunately I don't have
- 10:18any screenshot for other sensitive
- 10:19permissions but in the past I've seen
- 10:21credentials with access to history
- 10:23history bucket lumped up functions even
- 10:25an access to dinner mode DB tables in
- 10:28ETC there are so many things that might
- 10:31go wrong
- 10:33all right so there is a chance that the
- 10:37honor quanticated role is explicitly
- 10:39disabled in the console so in that case
- 10:42when you attempt to generate an identity
- 10:44ID like in the previous step it will
- 10:47actually throw the following error and
- 10:49authenticated access is not supported
- 10:51for this identity poll but later in the
- 10:54talk I'll show you another
- 10:55misconfiguration that you may actually
- 10:57leverage to to obtain and to get an
- 11:00account on an application that does not
- 11:02provide any user signup or registration
- 11:04so just be patient
- 11:07all right so in in that case assuming
- 11:11that you do have an access to that
- 11:13authenticated account once you log into
- 11:15your account just keep an eye out for
- 11:18this API call that is exchanging the ID
- 11:20token as you can see in this screenshot
- 11:22and it is exchanging the ID token into
- 11:24temporary AWS credentials similarly you
- 11:27can just use the tools that I've shown
- 11:28you to fetch the permissions associated
- 11:30with these credentials and see if there
- 11:32are loads any further access to their
- 11:34AWS services
- 11:36all right let's get to the second
- 11:38misconfiguration
- 11:40uh the second one is when the
- 11:42application does not allow sign up or
- 11:44any self registration let's say you have
- 11:46a SAS app or an admin portal for which
- 11:49the user provision is only done by an
- 11:52administrator
- 11:53they might not have it implemented any
- 11:56public signup for example from but they
- 11:59have lift this sign up API action
- 12:01enabled in the deep in the AWS console
- 12:04which is misconfiguration
- 12:07uh so from my personal experience signup
- 12:11is always enabled by default uh when
- 12:13creating a user pool in the console so
- 12:16as unless you explicitly disable it an
- 12:20attacker will can Leverage The cognitive
- 12:22API endpoint in order to sign up and
- 12:25provision an account for themselves
- 12:28how we can do that so to do that to test
- 12:32against this particular misconfiguration
- 12:34you will need the application client ID
- 12:37which is usually hard-coded in the
- 12:39source code AS we've seen before and
- 12:42also you need the client ID which is
- 12:44usually sent over to Cognito API when
- 12:47you try to log in to your account so
- 12:49it's easier to find just use burpswich
- 12:51then you will simply next send an API
- 12:54call to sign up with your email address
- 12:57using the AWS client of course if the
- 13:00sign up is lift enabled misconfigured
- 13:02then you should receive E6 DJ code to
- 13:05your email address that you used for
- 13:06sign up
- 13:08so but as you can see here uh in the
- 13:12screenshot here the this is a field sign
- 13:14up below but in the middle you can see a
- 13:16successful sign up that says that we we
- 13:19should receive a code or email
- 13:22so
- 13:24oh by the way uh if you don't want to
- 13:27use AWS client you can always send just
- 13:30direct HTTP call to Cognito API endpoint
- 13:33as follow as you can see here in the
- 13:34screenshot so this is just a replacement
- 13:36if you don't want to use AWS client you
- 13:39can construct this HTTP request make
- 13:42sure you're using the upper create HTTP
- 13:44header for sign up here as you can see
- 13:46and the body is properly formatted in
- 13:49Json so this is exactly the same as
- 13:52using AWS client I prefer the AWS client
- 13:54to be honest it's pretty easy
- 13:57all right so if the email verification
- 13:59is also enabled
- 14:01you will you won't be able to access
- 14:04your the account unless you confirm it
- 14:06but that is quite easy so you can again
- 14:09leverage AWS client Again by simply
- 14:12providing the email address the client
- 14:14ID the region and the six digits that
- 14:17you received in the email once you hit
- 14:19enter it will confirm your account so
- 14:23it's pretty easy to confirm it that's
- 14:25not a problem sometimes you might be
- 14:26able to sign up you get an account but
- 14:29it doesn't have any roles any role
- 14:32assigned to it unfortunately that could
- 14:34happen
- 14:35but there is a chance that uh
- 14:40well so oh sorry
- 14:44this is the so basically if you want to
- 14:47confirm your account you can all also
- 14:48use the HTTP request here so what I was
- 14:52saying earlier is that there is a chance
- 14:53that sometimes when you sign up the user
- 14:55doesn't have any group assigned so you
- 14:58will not get any access to the
- 14:59application features or functionalities
- 15:01but this is but in this particular case
- 15:04you can still use the generated
- 15:05credentials and test them against
- 15:07liberal permissions as we've seen in the
- 15:10first misconfiguration
- 15:12all right a third misconfiguration
- 15:14another prominent one is that you can
- 15:17come across uh writable sensitive user
- 15:20attributes
- 15:22so basically when you create a user pool
- 15:24in the console it allows you to set up a
- 15:26number of standard user attributes such
- 15:28as email full name birthday phone number
- 15:31Etc these are supported by default and
- 15:34these attributes are usually writable
- 15:37which means that the user can update
- 15:39them at any given time however the
- 15:42developer has the ability to create
- 15:45custom user attributes
- 15:48as you can see here you can create
- 15:49custom attributes uh like the user role
- 15:53it's a custom attribute that I'm
- 15:55creating here in screenshot to store the
- 15:57role and level of access of the user
- 16:00which they're supposed to have but what
- 16:02can go wrong here a lot actually
- 16:05so the security issue is that developers
- 16:07often forget to set sensitive user
- 16:10attributes as readable only
- 16:12so they leave them they they leave them
- 16:16as writable which means that even if the
- 16:18application he does not allow the user
- 16:21to change its value they can always
- 16:23Leverage The cognitive API to update it
- 16:26as we've seen in earlier examples
- 16:28so a lot can go wrong since the user can
- 16:31update their role for example to an
- 16:33admin or change their membership status
- 16:35or Etc depends
- 16:38all right so how we can do that how we
- 16:40can update uh the user attribute so the
- 16:43first step is to fetch the current
- 16:45user's attribute and see if there are
- 16:47any custom ones that they are not
- 16:49supposed to update
- 16:50uh so once you're logged into your
- 16:52account you will obtain an access token
- 16:55as you can see here in the authorization
- 16:56header then you can just copy it and
- 16:59simply execute the ews command to get
- 17:02the user attributes it will look
- 17:04something like this in the screenshot so
- 17:06you can see all the user attributes that
- 17:08are supported your own you can see that
- 17:10your own information there so upper
- 17:13apart from the standard ones always look
- 17:15for the attributes that start with the
- 17:18word custom
- 17:20okay
- 17:21so you can directly all you can also
- 17:24directly call the coordinator API if you
- 17:26don't want to use the AWS client to fix
- 17:28the user attributes so you would you
- 17:30want to look out for attributes that
- 17:32start with custom as I mentioned example
- 17:35of custom error reviews that I've come
- 17:36across personally are like is admit
- 17:39custom is admin uh user role is active
- 17:43is approved access level and these are
- 17:45all sensitive as they control the user
- 17:48level of access most of the time
- 17:51and naturally the next step is to try to
- 17:55update these attributes and see if they
- 17:58are only readable or also lived as
- 18:01writable which is bad so you so uh you
- 18:05can use the AWS commands as as posted
- 18:09there or you can just use the HTTP
- 18:11request to update it so if one like if
- 18:15it succeeded see if it succeeds you will
- 18:17get a 200 okay status
- 18:21here we've been we try to update the
- 18:24user role from a standard one to an
- 18:27admin so change the value to admin and
- 18:31like yeah funny enough funny story just
- 18:34when my talk was actually announced I
- 18:36had someone from the Bad Bunny Community
- 18:37Reach Out and share the critical bug
- 18:40that they found just exactly by updating
- 18:43the their user role to Super admin and
- 18:46so basically they found in the JS file
- 18:49that there is a role called super
- 18:50adamant right and they just like hit the
- 18:54API Cognito as you can see in the
- 18:57message here uh to update their their
- 19:00role to a super admin and luckily enough
- 19:03they just became the admin of the
- 19:05platform so this is pretty common in my
- 19:07boundaries and even when you're doing
- 19:08penetration testing as well it's pretty
- 19:10common
- 19:11the last one the fourth misconfiguration
- 19:14uh I've that I've come across is when
- 19:16the application these are lows I mean
- 19:18doesn't allow updating the email address
- 19:21as you can see here in the screenshot
- 19:23but I mean there are both clients and
- 19:25even server-side checks but it is always
- 19:28again possible to change it through the
- 19:30API cognito
- 19:32so you just need to get your own access
- 19:34token when you're logged into your
- 19:36account and then execute the ews command
- 19:39to set a new email address so you can
- 19:42always change it using the API Cognito
- 19:44API
- 19:46so there are some applications that do
- 19:48not really require email verification
- 19:50because they do not expect the user to
- 19:53be able to change it in the first place
- 19:55so this can be done from the AWS console
- 19:57as you can see uh and for apps that rely
- 20:01on email domain for granting the user
- 20:03special permissions or access this will
- 20:06definitely be passed the check controls
- 20:08and result in that privilege escalation
- 20:11is pretty easy
- 20:13so even when email verification is
- 20:15indeed required uh like a lot of
- 20:18applications do actually require
- 20:19verification there is another problem
- 20:22that arises is that the email attribute
- 20:25value as you can see here is already
- 20:27changed and said to the new unverified
- 20:30email address so although the email
- 20:32verified attribute does say that the
- 20:35email is not confirmed here it is false
- 20:38but
- 20:40the best security practice is just to
- 20:42never update the email until the user
- 20:44verifies it
- 20:47so what I've noticed uh with Cognito is
- 20:50that the user would successfully still
- 20:52be able to log in with the unverified
- 20:54email address so if that the application
- 20:57is not checking the email verified
- 20:59attribute this will definitely result in
- 21:02privileged installation it's pretty easy
- 21:04so you should always check the email
- 21:07verified if it's set to true or false
- 21:10uh for this particular reason ews they
- 21:13recently introduced a new security
- 21:15configuration which is unfortunately now
- 21:18enabled by default and understanding
- 21:20it's usually still confusing to most
- 21:22people so basically uh if you enable
- 21:25this security feature uh the email
- 21:27attribute will not be updated until the
- 21:30user has verified it which is the way to
- 21:32go but most applications still have it
- 21:35disabled especially because it's new the
- 21:37configuration is new and just still not
- 21:39enabled by default from my experience
- 21:41from what I've seen
- 21:43so we'll take uh this report on hacker
- 21:47one it's public report as a quick case
- 21:49study just to illustrate this
- 21:51misconfigurations uh that I just
- 21:54mentioned so the researcher here was
- 21:57able to achieve uh E4 account takeover
- 21:59on Flickr which is uh I think it's a
- 22:02Yahoo acquisition
- 22:04so just by abusing Cognito and they paid
- 22:06him 7.5 K just for it being a critical
- 22:09bug
- 22:11so I tried to summarize everything in
- 22:13this slide here so basically we have our
- 22:17victim user with the email Jack at
- 22:19domain.com
- 22:21so Flickr app was not allowing email
- 22:23update it was not a loan user to change
- 22:25their email but the researcher as I met
- 22:28I told you before he managed to change
- 22:29it just using the cognitive API it
- 22:32doesn't matter if there is like a client
- 22:33or server side Chase as long as he you
- 22:36can always use the cognitive Epi as
- 22:38demonstrated earlier so they updated
- 22:40their email to Jack at dominion.com but
- 22:44notice that Jack with a capital J which
- 22:47is the same email as our victim but with
- 22:49a capital J remember that so here there
- 22:52are two misconfigurations first one is
- 22:54that the email address attribute was
- 22:56lift writable it was lift with the
- 22:58writable permission in the console so it
- 23:00did not matter if it was disabled in the
- 23:02app since you can always update it from
- 23:04the Cognito API and the email second one
- 23:08is the email was Lyft case sensitive
- 23:10which they could have changed to
- 23:11insensitive in the console so that one
- 23:13was that were those were two
- 23:15misconfigurations
- 23:16then the researcher managed to
- 23:19successfully log in with the unverified
- 23:22email they have not verified the email
- 23:24but they still managed to log in with it
- 23:27so two issues arise one is the email
- 23:29verified attribute was not checked if it
- 23:32was set to true and the second one is
- 23:35the previous security configuration was
- 23:37not enabled either so otherwise if they
- 23:40enabled the previous security
- 23:41configuration they mentioned the email
- 23:43value wouldn't have been updated until
- 23:46you the user verified it so the last
- 23:49piece of the puzzle was the fact that uh
- 23:52there was an email normalization
- 23:53happening uh at the application Level so
- 23:57the capital J was changed to smaller J
- 23:59so the email matched the victim's email
- 24:02and the attacker was just able to log
- 24:04into the victim's account easily as you
- 24:07can see it is pretty easy to mess up
- 24:09things when you're configuring Cognito
- 24:10so it's very important to be very
- 24:13careful
- 24:15so here I have some recommendations for
- 24:16developers uh this one I've seen so far
- 24:20these are some recommendations always
- 24:22remove sensitive details from server
- 24:24responses any unnecessary details just
- 24:27remove it if you're not using sign up if
- 24:30it's not needed disabled in the console
- 24:32as well make sure you disable
- 24:34unauthenticated roles if they are not
- 24:36required uh always review the
- 24:39permissions that are associated with the
- 24:42authenticated and unauthenticated role
- 24:44and always always ensure the least
- 24:47privileged access that like always Grant
- 24:50the user minimum privilege access
- 24:52and then evaluate will evaluate all the
- 24:55user attributes and if they do not need
- 24:58to be updated disable the writing
- 25:00permission if not necessary and remember
- 25:02that the email clean I mean the email
- 25:05attribute can always hold an unverified
- 25:08email address as we have seen in the
- 25:10report that we just mentioned
- 25:14that's it thank you so much for tuning
- 25:15in appreciate it reach out on Twitter if
- 25:18you have any questions or anything or
- 25:20just check out my website and you can
- 25:22always contact me from there as well
- 25:24thank you so much
About this transcript
This page contains the full transcript of #NahamCon2022EU: Hunting for Amazon Cognito Security Misconfigurations by@yassineaboukir by NahamSec, generated from the public captions YouTube serves with the video. The transcript has 3,991 words across 608 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.