> For the complete documentation index, see [llms.txt](https://j0luuuu.gitbook.io/ctf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://j0luuuu.gitbook.io/ctf/kpmg-ctf-2023/policy-patrol_iam.md).

# Policy-patrol\_IAM

## Description

> You'll assume the role of a vigilant security professional responsible for evaluating and enhancing IAM policies. Your objective is to identify potential security gaps across AWS accounts.\
> `kpmg-ctf2.s3.ap-south-1.amazonaws.com`

## Solution

* Open the given s3 bucket link, it gives an xml file listing all the files in the bucket.
* We can also list the bucket contents using the AWS cli:\
  `aws s3 ls s3://kpmg-ctf2 --no-sign-request`
* Going through the files we find an interesting file named `aws.json`
* It contains the **AWS Access Key ID** and **Secret Access Key** for an IAM user:\
  `/resources/flash_cards/aws.json`
* We can setup a profile using the **AKID** and **Secret Access Key**\
  `aws configure --profile KICTF`
* Enter the Access Key ID and Secret Access Key (**DONT FORGET TO CONFIGURE THE REGION!!!**)
* We can now use this tool to enumerate the IAM policies for the profile: [IAM Enumerate](https://github.com/andresriancho/enumerate-iam)
* We get the flag in one of the policies with the name `kpmg_flag`

![flag](https://1613628666-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FKkuxWaWwvkRd57ql1rtY%2Fuploads%2Fgit-blob-1bd4a9e944fb525d3b2c51fc1f25aa935846d1fe%2Fflag.png?alt=media)

* Flag:\
  `KPMG_CTF{d2570462521936fc5330823c43781fca}`
