Back to Cloud

Challenge archive / Cloud

Terraform State Exposure

Original description

You have gained access to a low-privileged "guest" container in a company's cloud environment.

The company uses S3 for logs and infrastructure management, and a custom "SecureVault" system for secret management.

Your mission is to find a way to escalate privileges and access the high-value production secrets stored in the vault.


Original hints

Hints are preserved as part of the record. Point costs refer to the original competition.

Hint 10 PTS ORIGINALLY

Start by listing what S3 buckets are available in this environment using 'aws s3 ls'.

Hint 25 PTS ORIGINALLY

Developers often leave breadcrumbs in deployment logs. Look for any log files that might reference internal systems or file paths.

Hint 310 PTS ORIGINALLY

Terraform state files (.tfstate) are JSON files that contain EVERYTHING about the infrastructure, including IAM keys in plain text.

Hint 415 PTS ORIGINALLY

Operational exploitation instructions are omitted from this overview.

Hint 520 PTS ORIGINALLY

Operational exploitation instructions are omitted from this overview.

Hint 650 PTS ORIGINALLY

Not everything is useful: Focus on the CURRENT terraform state found in the 'prod' folder of the logs/backup bucket.