Description#
A developer accidentally committed a Google Cloud identity’s key to a public repository. You’ve been tasked with investigating an attacker who used the compromised identity attached to the exposed key to carry out some nefarious activities.
Check the challenge here.
Solution#
We are given an archive containing a JSON file called gcp.json.
Task 0: What Google Cloud identity is compromised?
The first two questions are easy to answer because the relevant information appears in the first few lines of the file.

Flag: main-dev@cyberwox-labs.iam.gserviceaccount.com
Task 1: What IP address is the identity authenticated from?
Flag: 160.238.37.7
Task 2: What country does the IP originate from?
I used iplocation.net to find the location of the IP address from the previous task.

Flag: South Korea
Task 3: What is the name of the firewall rule the attacker attempted to create?
I searched for the word firewall in the file and found this:

We can see that the attacker used the method v1.compute.firewalls.insert, and the compute.firewalls.create permission was granted. The name of the firewall rule is projects/cyberwox-labs/global/firewalls/default.
Flag: default
Task 4: What priority was the firewall rule?
Scrolling further down from the previous entry shows more details about the firewall rule, including its priority.

Flag: 0
Task 5: How many times did the attacker attempt to create GCE instances?
To count how many times the attacker attempted to create an instance, I used this command:
jq -r '.[] |
select(.protoPayload.methodName == "v1.compute.instances.insert" and
.protoPayload.status == null) |
[
.timestamp,
.protoPayload.authenticationInfo.principalEmail,
.protoPayload.requestMetadata.callerIp,
.protoPayload.methodName
] |
@tsv' gcp.jsonThis prints information about each request that called the v1.compute.instances.insert method. The entries with a null status are the initial requests, so they can be counted as separate creation attempts.
The output shows three requests:
2023-06-30T07:27:27.050776Z main-dev@cyberwox-labs.iam.gserviceaccount.com 160.238.37.7 v1.compute.instances.insert
2023-06-30T07:28:05.769654Z main-dev@cyberwox-labs.iam.gserviceaccount.com 160.238.37.7 v1.compute.instances.insert
2023-06-30T07:30:41.239392Z main-dev@cyberwox-labs.iam.gserviceaccount.com 160.238.37.7 v1.compute.instances.insertThere were three attempts, all originating from the same account and IP address.
Flag: 3
Task 6: What was the first region the attacker attempted to create the instances in?
I used the following command to print the resource names from the instance creation attempts. These names include the zones where the attacker tried to create the instances:
jq -r '.[] |
select(.protoPayload.methodName == "v1.compute.instances.insert" and
.protoPayload.status == null) |
[
.timestamp,
.protoPayload.authorizationInfo[0].resourceAttributes.name
] |
@tsv' gcp.json | sort
# Results:
2023-06-30T07:27:27.050776Z projects/cyberwox-labs/zones/europe-west1-b/instances/crypto-instance
2023-06-30T07:28:05.769654Z projects/cyberwox-labs/zones/europe-west1-b/instances/crypto-instance
2023-06-30T07:30:41.239392Z projects/cyberwox-labs/zones/us-east1-b/instances/crypto-instanceFlag: europe-west1-b
Task 7: Were any of the instances created? (Yes/No)
I used this command to print the status code and status message for each attempt:
jq -r '.[] |
select(.protoPayload.methodName == "v1.compute.instances.insert" and
.protoPayload.status != null) |
[
.timestamp,
.protoPayload.status.code,
.protoPayload.status.message
] |
@tsv' gcp.jsonThe results show that all three attempts failed because the project had no available GPU quota:
2023-06-30T07:27:36.256986Z 8 QUOTA_EXCEEDED
2023-06-30T07:28:12.847224Z 8 QUOTA_EXCEEDED
2023-06-30T07:30:49.443219Z 8 QUOTA_EXCEEDEDFlag: No

