Skip to content

Conversation

@sebastian-mora
Copy link
Contributor

This PR adds a new blog post under the AWS privilege escalation section. It highlights how overly permissive trust policies that don’t restrict by trust anchor or certificate attributes in IAM Roles Anywhere can be abused by with any valid certificate to escalate privileges.

@carlospolop
Copy link
Collaborator

This is great, thanks @sebastian-mora
In any case I'll be moving this to the STS privilege escalation section

@carlospolop carlospolop merged commit 9b9670e into HackTricks-wiki:master Jun 24, 2025
github-actions bot pushed a commit that referenced this pull request Aug 29, 2025
Adding page for IAM Roles Anywhere Privesc
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants