↓ Skip to main content
  1. Writeups/
  2. Hack The Box/

Google_Cloud_Incident

Tools: Jq

Description
#

A developer accidentally committed a Google Cloud identity’s key to a public repository. You’ve been tasked with investigating an attacker who used the compromised identity attached to the exposed key to carry out some nefarious activities.

Check the challenge here.

Solution
#

We are given an archive containing a JSON file called gcp.json.


Task 0: What Google Cloud identity is compromised?

The first two questions are easy to answer because the relevant information appears in the first few lines of the file.

Task 0 Image

Flag: main-dev@cyberwox-labs.iam.gserviceaccount.com


Task 1: What IP address is the identity authenticated from?

Flag: 160.238.37.7


Task 2: What country does the IP originate from?

I used iplocation.net to find the location of the IP address from the previous task.

Task 2 Image

Flag: South Korea


Task 3: What is the name of the firewall rule the attacker attempted to create?

I searched for the word firewall in the file and found this:

Task 3 Image

We can see that the attacker used the method v1.compute.firewalls.insert, and the compute.firewalls.create permission was granted. The name of the firewall rule is projects/cyberwox-labs/global/firewalls/default.

Flag: default


Task 4: What priority was the firewall rule?

Scrolling further down from the previous entry shows more details about the firewall rule, including its priority.

Task 4 Image

Flag: 0


Task 5: How many times did the attacker attempt to create GCE instances?

To count how many times the attacker attempted to create an instance, I used this command:

jq -r '.[] |
  select(.protoPayload.methodName == "v1.compute.instances.insert" and
    .protoPayload.status == null) |
  [
    .timestamp,
    .protoPayload.authenticationInfo.principalEmail,
    .protoPayload.requestMetadata.callerIp,
    .protoPayload.methodName
  ] |
  @tsv' gcp.json

This prints information about each request that called the v1.compute.instances.insert method. The entries with a null status are the initial requests, so they can be counted as separate creation attempts.

The output shows three requests:

2023-06-30T07:27:27.050776Z  main-dev@cyberwox-labs.iam.gserviceaccount.com  160.238.37.7  v1.compute.instances.insert
2023-06-30T07:28:05.769654Z  main-dev@cyberwox-labs.iam.gserviceaccount.com  160.238.37.7  v1.compute.instances.insert
2023-06-30T07:30:41.239392Z  main-dev@cyberwox-labs.iam.gserviceaccount.com  160.238.37.7  v1.compute.instances.insert

There were three attempts, all originating from the same account and IP address.

Flag: 3


Task 6: What was the first region the attacker attempted to create the instances in?

I used the following command to print the resource names from the instance creation attempts. These names include the zones where the attacker tried to create the instances:

jq -r '.[] |
  select(.protoPayload.methodName == "v1.compute.instances.insert" and
    .protoPayload.status == null) |
  [
    .timestamp,
    .protoPayload.authorizationInfo[0].resourceAttributes.name
  ] |
  @tsv' gcp.json | sort

# Results:
2023-06-30T07:27:27.050776Z  projects/cyberwox-labs/zones/europe-west1-b/instances/crypto-instance
2023-06-30T07:28:05.769654Z  projects/cyberwox-labs/zones/europe-west1-b/instances/crypto-instance
2023-06-30T07:30:41.239392Z  projects/cyberwox-labs/zones/us-east1-b/instances/crypto-instance

Flag: europe-west1-b


Task 7: Were any of the instances created? (Yes/No)

I used this command to print the status code and status message for each attempt:

jq -r '.[] |
  select(.protoPayload.methodName == "v1.compute.instances.insert" and
    .protoPayload.status != null) |
  [
    .timestamp,
    .protoPayload.status.code,
    .protoPayload.status.message
  ] |
  @tsv' gcp.json

The results show that all three attempts failed because the project had no available GPU quota:

2023-06-30T07:27:36.256986Z  8  QUOTA_EXCEEDED
2023-06-30T07:28:12.847224Z  8  QUOTA_EXCEEDED
2023-06-30T07:30:49.443219Z  8  QUOTA_EXCEEDED

Flag: No

Vlad Șteopoaie
Author
Vlad Șteopoaie
A.K.A. h3pha