4 ms·
So, I've recently been evaluating AWX for my workplace. Thus, making sure it's secure is definitely important to me. That said, I'm having a hard time seeing h
by jerrac 9y ago
So, I've recently been evaluating AWX for my workplace. Thus, making sure it's secure is definitely important to me.
That said, I'm having a hard time seeing how a compromised browser access AWX could give anyone full access to everything. Attackers could effect anything a playbook has access to, but considering how varied playbooks are, it would be really hard to guess the right values to pass into a job to get what you want.
Can someone elaborate on how an attacker could do real damage using a browser based attack?
- deleted 9y ago[deleted]
- ibotty 9y agoSimply add to any playbook a play with `all` hosts that drops your remote shell.
- AlanSE 9y agoYou would need source control access to do that.
- jerrac 9y agoI had thought of the shell module. But the attacker would still have to know your playbook is using that module, and they'd have to know the variables you are passing into that module in order to override them. So, can you explain how an attacker would figure that information out? Assuming the playbooks are stored in source control like the Tower docs recommend, and all your variable values are mostly in source control as well.