/srv/irclogs.ubuntu.com/2024/01/28/#cloud-init.txt

holmanbminimal: hahaha03:17
holmanbuserdata _is_ root03:18
holmanbcloud-init isn't doing any privilege escalation there03:22
holmanbThe article starts with:03:22
holmanbIf an adversary has access to the modify-instance attribute permission they can leverage it to escalate to root/System on an EC2 instance.03:22
holmanbWhich is just silly because modify-instance can do things like modify the kernel/initrd/etc03:23
holmanbI've seen around a dozen articles that say similar things and they all have one thing in common: a misunderstanding of cloud-init (or in this case the cloud)03:27
holmanbIf you can already modify the kernel, you have root already - cloud-init is completely irrelevant. 03:30
holmanbIt's equivalent to saying "assume you have root, then escalate to root" 03:40
=== tds0 is now known as tds

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!