5 ms·
This is a helpful writeup in terms of specific queries to look out for, but any RCE on a host with privileged IAM access is going to lead to this scenario. > T
by cddotdotslash 5y ago
This is a helpful writeup in terms of specific queries to look out for, but any RCE on a host with privileged IAM access is going to lead to this scenario.
> The AWS account takeover was possible because a highly privileged IAM role had been assigned to the EC2 instance running the vulnerable Docker container app
This attack isn't unique to Log4Shell; it's a symptom of giving your (compromised) EC2 instance global admin access.