The day has finally arrived! HackTricks ARTE (AWS Red Team Expert) cert is now available at https://training.hacktricks.xyz/ !
We've opened 100 spots with an early bird discount, don't miss yours!
HackTricks Training
1 messages · Page 1 of 1 (latest)
The day has finally arrived! HackTricks ARTE (AWS Red Team Expert) cert is now available at https://training.hacktricks.xyz/ !
We've opened 100 spots with an early bird discount, don't miss yours!
HackTricks Training
@modest elbow Is there dedicate channel for people who registered?
When I asked this yesterday he told me it was this channel.
@modest elbow Access Key/Secret Access Key not showing up in the IAM labs section as shown in the Labs presentation. Where do we get the creds to access the labs if they're not showing near the lab exercises below the video?
I've also raised a ticket for the same thing - hoping its a simple fix
Awesome, thank you. How do we submit tickets?
there's a training support channel
also if you add your discord handle (check as some start with a period) from here into your profile on the training website it will give you access to the #arte-general channel as well
@reef orbit See above ^
How to contact support or ask technical questions in a training.
If you have an active course, you can can go to your user profile in https://training.hacktricks.xyz/profile and add your Discord handle. This will add you to a new role in this server where you will be able to find new channels to open support tickets or ask questions.
Asking here since I guess this is a common question for the whole training platform: Is there any way to get a full invoice for the voucher payment? After I bought mine, I got the quick receipt via email, but I see nothing else. Maybe I missed something?
Thanks for asking! We have just added this option, however it's only valid for new purchases. If you already bought the voucher, just open a ticket and we will generate one manually for you
need quick help, if you know there is attached policy for specific user and want to check what exactly that policy looks like via CLI how should we check this?
Also how do we know user has iam:SetDefaultPolicyVersion permissions...
am able to see the policy name, using versions you can check version as well, but whats inside that policy? how do we check
There's no need, ever, to cross-post a question
i thought it be wrong group 😉 hence posted twice
So you delete it from the channel where it's irrelevant, and keep it in the one where it is
done .
You should have enough permissions to see what is inside your policies in (almost) every lab. This way you know what you can exploit.
You might not bee able in specific ones like the BlackBox one, as it's intended to be more "realistic".
Please open a support ticket if you find some lab where you cannot see this information!
Hey, just making sure, if I signed up now, I'd get access to labs immediately right?
I still see the first 100 haven't signed up but want to make sure that if I paid, I wouldn't get put on a wiatlist
@modest elbow
I'd like to begin right away!
Hey!
Not exactly, you can buy a voucher now with the discount and use it whenever you want (right away or next month for example)
There is no waitlist at the moment
oh perfect!!!
Pays immediately.
❤️
I have to mention, HackTricks has been an amazing educational resource for me, I think what you're doing is fantastic
Also, do you have some time for a quick DM?
I have a couple questions regarding something that I would prefer to keep off the public channel
Not about HackTricks
thanks mate, sure. About the dm sure, send it
Hi @modest elbow ! I am considering to purchase the course and looking to clear a couple of doubts I have.
Please let me know. Thanks in advance!
Hi @empty topaz
Thank you for your response! #purchased
Thanks! Let us know how you find it
Hey guys, so far I'm loving the course! Quick question, for the EC2 labs, are the instances up when the lab is running?
Once the lab says provisioned everything is running 24/7 (this might change in the future). Also for lab questions the #arte-general channel is more appropriate
How do I get access to that channel
If you bought the course and activated it you can go to your profile page in the training platform and update your discord handle. You will automatically be added to the ARTE channels
Hi @modest elbow @glacial kelp I bought the ARTE training course and started it yesterday, I also added my discord handle to my profile, but I wasn't added to the ARTE channels just yet. Could you please check if there are any issue? Thank you
Looking into it
looks like your discord handle in the platform is set to a weird number it should be gelbezitrone
just modified, thank you
Hello,
I purchased ARTE training and added my discord handle to my profile, however, I am not added to the channel. Could you please help me with that?
Thank you
@limber sand ensure.you are putting ayaka_81050
Now I am added to the group, thank you!
Afternoon everybody! Quick question regarding the extra credit for the ARTE class. Does the pull request have to be specifically about AWS, or can it be about other cloud environments like Azure or even Digital Ocean?
Yes, the goal os to show your expertise in AWS to reduce 1 flag.
Ince we realease courses for other clouds we will do the same with them
I understand, thank you! Is there a timeline on when those other courses are released?
We are expecting to release GCP and Azure this year.
In any case feel free to send the PR if you want and remind us to apply the flag reduction in the future whenever you do the course!
Hi @carlospolop @glacial kelp I bought the ARTE training course and started it yesterday, I also added my discord handle to my profile, but I wasn't added to the ARTE channels just yet. Could you please check if there are any issue? Thank you
Hi I see in the DB you set the discord handle with the #xxxx try without it. If that does not work try moose_enthusiast I'm not sure now what discord's API recognises as your username
How perfect! I came here to ask the same question on it! Will be eagerly waiting for the Azure and GCP ones!
Hey all! Curious how the ARTE course has been for those taking it. I’m currently doing the AWS CloudBreach course
Hey all, I just finished the HackTricks ARTE exam.
This was a great course and exam, OSCP style (despite a small reset issue at the beginning, quickly addressed by congon4tor).
Really great course, good instructional up-to-date content in the videos, written documentation via Cloud HackTricks, linked resources to original research, great exercises with cool flag system.
I've done a ton of remote trainings (OSCP, OSCE, CRTO, SANS courses etc; I'm holding 17 certs) - including the ones from Altered Security for offensive stuff in on-prem AD and Azure as well as as CloudBreach's AWS and Azure courses. CloudBreach pales in comparison. ARTE was hands down one of my best training experiences. Already am recommending this to my colleagues. 10/10
I was wondering about CloudBreach.
That one you have to like set the labs up yourself with their terraform files right?
No, you don't have to provision anything in your own account, but are on shared infrastructure. It is a good course with one nice, clear attack path detailed in a single PDF document, but really a different experience compared to ARTE in breadth and depth, with your own big lab environment here.
Oh cool, yeah, with ARTE so far (I am just past beanstalk and onto codebuild) I've learned about so many different attack paths, and based on my prior knowledge of AWS exploitation it's only expanded into even more and I already knew how like compromising EC2 can lead to access of a lot of different services and stuff, but like had no clue about a bunch of these other services.
So like, now with that expanded knowledge, I feel like I am more prepared to tackle more elaborate AWS environments, and better yet, even environments of which there aren't labs in ARTE for because of how well documented https://cloud.hacktricks.xyz/ is.
I know I can just go there and research how to enumerate the service, I can also go to AWS's website do some research there, and find out what I can achieve through it.
or replace the instance profile of the compromised instance (ec2:ReplaceIamInstanceProfileAssociation). *
aws ec2 replace-iam-instance-profile-association --iam-instance-profile <value> --association-id <value>
``` There is a error. The right query is :--iam-instance-profile Name=<value>
@modest elbow @glacial kelp
What is this about looks like your message is missing a first part?
Fixed! Thanks!
Anyone had trouble connecting to their RDS instance after launching it in rds-lab-2?
I set it to --publically-available and verifed that the instance is running
I figured it might be a security group issue but I can't ping
It is highly likely a SG issue
got the flag 😎
@everyone Friendly reminder that today is the last day of the early bird discount for the HackTricks AWS Red Team Expert cert! You can get a voucher today and redeem it within a year! More info in training.hacktricks.xyz
Did anyone else get a 502 bad gateway after uploading their app on the Elastic Beanstalk lab?
Did you solve this? my guess is the service was not ready yet or it was failing to start
I ended up resetting the lab. Going to give it another shot later today
hi, I just entered the ARTE training. Is there a private channel for that? Sorry, I never used Discord before.
Yes! In you account settings https://training.hacktricks.xyz/profile set you discord handle and you will get access to the arte-general channel
It's weird because I tried reuploading literally the same thing I had pulled down with the exception of just adding a comment and it totally just throws 502
If you think something is broken feel free to open a ticket
I did that already. But then what?
In your case your discord handle is michael_45127 once you add that to your profile and save you will automatically get added to the correct discord role
thank you
Will there be an Azure training similar to ARTE in the future?
yes! We expect to release GCP and Azure this year
Hello I have sent an email to support about the AWS Red Team Expert labs, one of them seems to be broken.
Also, is there any consideration to give us a 60-day lab time? This would give us a chance to a complete 1 lab a day instead of 2 labs a day which is very demanding for people who are employed.
This would also leave people time to research the video contents. Please deeply consider this.
Hey @silent rune do you have access to the arte-general and training support channels? You might need to add your discord handle to your account in our website (in the profile page). There you can open a ticket so we can better assist you with any lab issues
Regarding extending the lab duration we are not able to cover the cost of the labs for 60 days without raising the price. For this reason we think it makes more sense to keep the certification cheaper with 45 days and in case people need it they can extend 15, 30 or 90 days.
I wouldn't think of x labs a day as a goal since there are labs that can be done in 10 minutes and others that will take multiple hours to figure out.
But we appreciate the feedback. We give a feedback form at the end of the certification so looking forward to seeing you opinions
Thank you, I will look for that. 🙂
@glacial kelp I added my handle to the profile section. I may need to open another ticket
I've been thinking about the issue you raised about lab costs. What if you start with the cheaper labs (like IAM, S3, Security Groups) and save the pricier EC2, RDS, DynamoDB labs for a separate provisioning cycle (like a part 2 of the course), making them on-demand..?
This way, we keep initial costs down and only use resources when needed, potentially extending lab access without a big price hike. It could balance cost management with a solid learning curve, offering flexibility for those needing more time. Thoughts?
I've been working on something along those lines. Still in early experimental phase
Why change the whole course for one person? I and many others think it's just fine the way it is. Having access to all the labs from day one is actually better for learning due to a process called interleaving and spaced repetition. So, if you limit it and break it into two courses that would be shitty overall experience simply because you don't want to spend some time on the weekends, and at night doing the labs. Not to mention you literally just started, so you don't even know how long it will take you @silent rune . Why not try it first before you complain and ask for changes?
I respectfully would like to respond to this:
"Why change the whole course for one person?"
"I and many others think it's just fine the way it is."
"break it into two courses that would be shitty overall experience simply because you don't want to spend some time on the weekends"
"Not to mention you literally just started"
"Why not try it first before you complain and ask for changes"
While I’ve purchased but not started the course yet, it sounds like @glacial kelp point was the lab would be too expensive to keep running for >45 days without raising the price. One way to reduce the infra cost is only spin up the infrastructure needed for the lab. Example, when lab one starts, it provisions lab one infra. When the flag is found it’s deprovisoned. In theory this could allow the course to remain the same price but extend the duration. Or the course authors could just keep the extra money 🤷🏻♂️
Guys, we are optimizing the labs so no worries about this. Labs will always be available from day 1 and the quality won't be affected
This is a valid and good suggestion as well. I agree.
Thank you. And we appreciate everything you do! This is only initial feedback, not poor reviews or anything. Keep doing great work, friend.
Also once the exam is passed we share a feedback form to collect opinions and ensure we keep improving as much as possible
totally stuck on blackbox-lab-1. ||When I simulate the group permissions I get nothing back. After adding my user to the group I get back the same permissions I had before when re-simulating.||
Blaclbox1
I respectfully would like to respond to
@modest elbow @glacial kelp hi ! do you know when the course on gcp will be available?
No official ETA yet, but it is in development probably before summer (or even sooner) but no promises
ok thx
hey, I'm just stucked on that way
I modified the database, the status is "active" but postgress seems not accessible
From ec2 instance on lab2 psql is not installed but with nc i am able to get a reply. How do you managed to get the access? seems like sg is denying trafic from public but not from vpc
nvm, got it ||ec2 has internet access, just download psql binary and there we go||
Hey guys with @hardy canyon we wrote a review of the certification for those who are interested ⬇️
https://www.hackcyom.com/2024/02/arte-review/
Summary Introduction Who is ARTE for? Certification Preparation The Exam Pros and cons Pros Cons Conclusion Introduction ARTE or htARTE is a certification issued by Hacktricks Training, a training organization created by Carlos Polop, who is also the creator of the famous hacktricks cheatsheet. The aim of the certification is to present differen...
Thank you for writing this I appreciate the feedback
what is this channel?
For people that have purchased the certification they can access some other channels
what certification?
Our hacktricks training AWS Red Team Expert
Hi all im unable to solve the sts lab 2. I am specifically stuck at running the github workflow where im getting errors unrelated to the lab.
Do we require aws as well?- tried referencing it including my aws arn
Any support would be appreciated
You only require a github account, check github docs on how to connect to aws from github actions using oidc
Thanks!
I am a noob, doing a challenge and have a png file; trying to learn from output of zsteg -all xyz.png am stuck, anyone who can help?
hey friends, someone can help me with some doubts with iam lab?
Please ask away (aviously try to keep spoiler free) and someone will try to help you
You should also have access to the #arte-general channel if you bought the course and configured your discord username in your profile in our website
Do we have a rough timeline for this?
I can't wait to do the Azure and GCP trainings
GCP + Workspace before summer and Azure+EntraID before the end of the year hopefully!
Friends, good evening! Who can help and sort out 2.2 STS - Security Token Service: Github Actions?
does ARTE have a written component in tandem with the videos?
slides yes
cool, are they comprehensive to stand on their own?
Yes, but the videos clarify everything, once you pay the course you have the content for ever, so I don't see why not to watch the videos
I recomend it
i absorb information better reading. not that i won't watch the videos, i just like having reference text. thanks!
probably going to give it a whirl
The cool thing about the videos is that you have examples of carlos creating / configuring / exploiting services, that you may not bee able without an AWS account.
As Slayer explained almost all videos have demos not represented in the slides
Hello, I added my discord handler to my hacktricks profile but I still don't have access to the training channel, can someone help?
Hey! @icy jewel how did you spell it? Discord is case sensitive for this... I believe you need to set it to tartof
Thanks for your answer, it works now !
hey @modest elbow I'm looking to do the ARTE when I have some time - do you have a timescale for the Azure version (I belive there was mention of Azure and GCP versions potentially)
We are expecting to release the GCP one in June and the Azure one at the end of the year!
We're excited to tell you about Nuclei Templates release v9.8.5! This new version includes newly added AWS cloud review templates. In this blog post, we'll discuss automating cloud misconfiguration review, creating custom AWS checks, and sharing results on the PDCP Cloud for review.
The AWS Cloud Security Configuration
Interesting 😎
A lot of checks are going to be automated with nuclei now I guess
Powerfull integration
Interesting nuclei took the time to do this. I thought they were more bug bounty related than for whitebox pentests. They don't have too many checks right now compared to prowler or steampipe but they will add more probably
I guess the good templates will be custom by the people like always
I hope they add cognito templates
It's also my favorite exploit
I found an 0day in a hack cracking platform by coalfire.
Based on Carlos's teachings!
Super exciting to have found that
🔥
Now, AWS came out and stated that they will change the pricing model! Time to run your sites behind custom 4xx pages to get massive discounts! (Not mine, found it somewhere on my Twitter feed)
I can't deploy "github actions" in STS module, though other sub modules are successfully deployed.
<@&937047799441268746> Please help check it
@tame knoll I will notify it thanks
Thx
Hey @tame knoll can you open a support ticket? You will need to add your discord handle to your profile in the website
Sure, will do
I have a question about sql injection wargame, can anyone take a question?
@everyone Discover Hacktricks Training AWS Red Team Expert Certification with John Hammond and Ignacio in https://buff.ly/4bllq3i
https://jh.live/hacktricks-arte || Get hands-on with AWS Red Teaming and tackle the HackTricks Training and ARTE course! https://jh.live/hacktricks-arteLearn...
Still on track for this @modest elbow ?
tight schedule but still on track!
@everyone
The best hacking course & cert in GCP and Workspace is coming to HackTricks Training!
Learn from the basics (organization hierarchy, permissions...) to expert level (how to escalate privileges, remain undetected, pivot between GCP and Workspace...) in the htGRTE course and certification (GCP Red Team Expert).
Soon we will be releasing the presale with an amazing early bird discount!
ohhhhhhhhhhhhhhhhhhhhhhhhh snap
nice
I'm so glad I've been here from the beginning to see how things are progressing, you're killing it @modest elbow and @glacial kelp !
Take my moneyyyyyyyyy
I AM EXCITED!!
Preparing myself to first blood the GRTE cert exam! 🔥
inb4u
Are there any cool attacks you can do if you only have a Google project ID? I keep finding these in mobile penetration tests that I do as a result of firebase db installations from the app. Being able to leverage that into an attack would be slick
Not directly, but there are some resources that can be publicly exposed and you need to know the project id to bruteforce potential names. So the project ID is useful to find other potentially vulnerable resources (there will be some labs about this in the new cert)
Any timeline for Azure (MARTE!!!??? :D) ?
hopefully for the end of the year
@everyone for those in Barcelona and interested there's a CTF game based on a 0day and serverless cloud environments within aws this Saturday 1.
It's free and there will be prices for the winners!
More info:
https://www.meetup.com/es-ES/hackingcybersecurity/events/300898931/?notificationId=1369556153578446848
https://www.meetup.com/es-ES/serverless-barcelona/events/300898832/
This CTF is a contest oriented to cloud and serverless services, where contestants have to work together to solve security and cloud/security challanges to win!
Teams will
👋 hi…what are the charges for lab extension if needed
I am in a full time job with limited time each day…do you think typically 60 days is more than sufficient or is that a chase to finish the course and labs
Additionally, if I take the course which is for life and at any point I just want to do the labs, is that possible without repurchasing the course but only the labs…also any new updates to the labs will be automatically also available to everyone that bought previously …is that right?
This is for ARTE and do we get a certification badge that can be verified by the employers
Last question 😅…are we taught any stealth and bypass in the course as well
Yes you do get a badge from either Credly or Accredible
Yes you are taught stealth techniques
Lab extension prices are on their website. 🙂
I read there is no badge..but instead a document with QR code
Yes on completion of the exam you get a pdf certificate with a qr code that can be used to verify in our website
Thnx
And can I buy the course today but go through the document and videos first and start the lab 2 weeks later…I think it’s not possible but just trying my luck
And can you also confirm if there’s any update or new topic added then that will also be covered under life time access to the course material ?
Unfortunately that is not possible lab time starts at the time you activate the course voucher
This is the case for videos and slides. Which we do update if behaviours change in AWS. For new labs if your lab time has expired you would need to buy lab time in order to do new labs
Ok 👍
Thnx
Hi @everyone ! The presale of HT GCP Red Team Expert (GRTE) is finally here!
Become a GCP and Google Workspace security expert by getting access to this certification with the early bird discount!
More information at https://training.hacktricks.xyz/courses/grte
(The certification is expected to be released with all the content and labs on July 22nd)
Nice
activate it at any point in the next year
this is nice
@modest elbow how long is the early bird offer valid for
We haven't decided yet, but potentially for the first 70 students getting it or so
When will the presale start?
It is already available
I see the same thing, that's why I asked too.
Hi Carlos, are you planning to give discounts at ARTE on the occasion of GRTE? I missed the first sale and it's a little over my budget so I've been waiting for a sale for a while.
Deploying a fix now it was set so only admins could purchase (for our testing) and I forgot to undo that
let us know when we can buy ❤️
July 22nd here we come baby 🏎️
Should be good now
damn I've having that stupid issue with international purchases again 😐
Is it possible to get student discount in early access voucher?
Moreover, do you have some plans for people who would like to buy ARTE + GRTE? @modest elbow
yep
Are there discounts for students?
Yes there are! Create an account using your universities email address, then send us an email from that email address to training-support@hacktricks.xyz asking for the discount and indicating a link to your linkedin and we will send you a 20% discount.
Yeah, I have seen that earlier but wondering if it also applies for early access
atm we have the discount HACKERMATE enabled with a 20% discount on ARTE thanks to the influencer hackermate
It's not possible to use several discounts at once, either early bird or other discounts.
And we have special discounts if several vouchers are bought in bulk (usually by companies). We might considder adding special packs in the future, but the early bird discount is the biggest discount we give, so atm it doesn0t make sense to create more discounts for GRTE
Any plans of issuing badges via badger or Credly?
We would like to do something like this in the future but have struggled to find the time to investigate what the best provider would be for us
Accredible or Credly seem to be the move for most businesses atm.
Both are above the pricepoint that makes sense for us at our scale. I'm adding a button in the certificates table that simplifies adding the cert to linkedin profiles
Hopefully that is good enough for the time being
@steady sentinel If you go to https://training.hacktricks.xyz/certificates you should see a new linkedin button which will take you to a prefilled form to add the certificate to your linkedin profile. You can add the PDF as Media and it should look pretty nice
Hi @glacial kelp @modest elbow, if I buy the ARTE voucher now, when should I activate it at the latest?
All vouchers have a 1 year expiration
Hey there @glacial kelp ! Super interested in the ARTE training. Is it possible to do a payment plan or installments for the voucher?
Hey, currently we are not able to support payment plans. We do have some student discounts if that helps
Hi all, I have trouble with provisioning the lab for AWS-Lambda, I have tried to rest the lab with no luck . Anyone can can help please.
Have you tried reseting the lab for that specific lesson or the entire lab account from the dashboard. Feel free to open a support ticket
I'll try the entire lab now - Thanks
I have problem on EC2 Labs, i configure aws:
aws iam list-users
{
"Users": [
{
"Path": "/",
"UserName": "ec2-......
[SNIP]
......
everything is good, but when i do:
aws ec2 describe-instances
Could not connect to the endpoint URL: "https://ec2.us-east1.amazonaws.com/"
What I'm missing? :/
look at what your policy allows
aws iam list-attached-user-policies --user-name <username> #this flag might be wrong?
aws iam get-policy-version v1 --policy-name <policy-arn>```
you may only be able to describe some instances
hi mates, just bought voucher for GRTE, am i right that it will be available after release on 22nd of July?
Yes! You will be able to redeem it from the 22nd of July and start the cert
Hi everyone, GRTE finally starts tomorrow, we are looking forward to it 🎉 Are you guys planning to do Azure RTE in the near future?
GRTE starts 22 of July not June, still 30 days to go
ok, thx)
But we are really happy with how it is turning out I think it is going to be great
If it's anything like ARTE it'll be fantastic
And hopefully teach me what I can do with all these keys for google projects I keep finding on pentests 😂
Hi, you give me an invoice when I purchase the training, right?
Yes, you receive an email from stripe with a link to download the invoice
Hey @modest elbow @glacial kelp, today, I bought ARTE but ran into a small problem. I have contacted training-support@hacktricks.xyz via email. I would be grateful for any assistance you can provide
Hey I'll DM you
Hello @modest elbow I am buying the voucher soon for expert aws cert, I have a couple questions kindly, 1. how long does each lab take per day, 2. is the exam guided (meaning that despite being black box, are there directions to what to exploit or to find?) 3. can i buy the voucher now and begin in few months?
Thank you
@glacial kelp eagerly waiting for your response :^)
Hey 👋,
Beautiful, thank you ❤️
@glacial kelp purchased, added discord id, will discord access be given shortly or only once the voucher has been activated?
Only when the voucher is activated
@everyone
ARTE (https://training.hacktricks.xyz/courses/arte) cert was just updated with new techniques in the Black Box (Red Team) and CloudTrail sections and a new Black Box lab was released!
Get it with a 20% discount using the "SUMMERTRAINING" code before the 1st of August.
If you already bought it, you have lifetime access to these updates. Go to those sections and check the updated slides and videos!
excellent lab, thanks guys. It broke my brain for a long time.
@glacial kelp please note I DM'd you about voucher questions further, about to activate it. kindly when you have a moment to get to it
T-15 DAYS UNTIL GRTE LAUNCH
🔐 Calling All Cyber Enthusiasts! 🔐
Are you passionate about cybersecurity? Eager to stay ahead of the digital curve? Look no further! Join our exclusive WhatsApp group where we share top-notch resources, insightful content, and cutting-edge techniques to keep your skills razor-sharp. 🚀
Whether you’re a seasoned pro or just starting your cybersecurity journey, this community is for you. Let’s learn, collaborate and elevate our skills together! 💻🔍🔒
join this invite link https://chat.whatsapp.com/J8HVeSEPDUR2gaE5NB4OoM Let’s fortify our knowledge and build a stronger, more secure digital wor
When I purchase the ARTE training, does the course start immediately or do I get to choose a start date? Thx
Once you buy it you will receive a voucher. That voucher can be redeemed any time within 1 year and once you redeem it the countdown will start!!!
SWEET DEAL!! Thanks!!
Wanna know if GRTE is worth to take it???
I'm definitely going to take ARTE, but I don't know how big the market size is for Google Cloud
Well
AWS, Azure and GCP take up like 90% (made up number, probably accurate) of the market share, so by preparing yourself for all three environments, you are then ready to handle assessments that many people just don't know how to do.
Good way to put it.
The GRTE cert is no only about GCP but also about Google Workspace which is one of the most used identity providers. And the companies that use Google Workspace tends to use GCP sooner or later just because it's easier. So even though it's just the hird biggest cloud provider, I find it being used pretty frequently (specially combined with AWS)
Combined market share is 67% in total, and GCP makes up 10%, so it's like half of Azure and 1/3rd of AWS.
So yeah it's pretty common, especially if you think about how often you see AWS and Azure nowadays.
And the multi-cloud / hybrid environments are increasingly more common as well
Thank you very much for the information. Im tend to be very new to the cloud but I found cloud hacking very interesting. Definitely going to get both bro.
💯
Yeah plus it's fun to learn new stuff 😄
To join the arte traning private group, do I have to purchase the course first
yes
thank you very much
T-M 24 HRs!!!
Hi,
There is a CORS error that prevents watching videos in the GRTE course.
I'll fix it in a bit sorry
This is resolved now
Lets go @everyone !! GRTE - GCP Red Team Expert- certification is finally live!
Get it with the early bird discount while it last!
And good luck to everybody that is trying to get first bloods of the labs and exam!
https://training.hacktricks.xyz/courses/grte
799€ which is wayyy more out of my budget.
Sry to hear that! But that will be the minimum price for a completely guided certification on hacking GCP and GWorkspace including novel techniques and tens of labs to practice!
Yh I know. 🥲
Got mine already! Also this time it was super easy to download the invoice :). I'm excited to start the labs in Aug 🚀
Anyone else having trouble deploying the lambda lab in ARTE?
If you get errors deployong labs try resetting your entire environment from the dashboard
Resetting the lab is triggering errors.
This occurred after the second deployment of the labs failed.
I was getting unable to deploy project/topic labs or somehting like that, reset my whole lab and it then failed.
second lab reset today and the deployment once again failed just now 😐
Fixed it for you but still investigating the root cause if anyone else has any issues please open a ticket
Found the root cause the lab destruction deletes that resource when it should not
Shold be fixed now. Please reopen a ticket if you find any issues
Hello. I'm stacked on "sts:GetFederationToken". I'm setting credentials to default profile and using custom script. But, Im getting eoor for accessdenied. Is there any change I shoud make the script?
https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-post-exploitation/aws-sts-post-exploitation#from-iam-creds-to-console
This question would be better suited for the #arte-general channel if you don't have access you will need to set your discord handle in the profile page in training.hacktricks.xyz
got it. thanks
Hi
GRTE labs - iam section, got multiple issue while trying start up the lab, after couple of lab restart it start working, now do not have possibility to extend lab time due to error, could You check it:
Hi, we are aware of this issue and are looking into it. The IAM lab should now be fixed.
For future occasions this would probably fit better in the #grte-general channel. If you don't have access you will need to add your discord handle in your profile page in the training platform
Do you mind moving this message to the #grte-general channel please
done
<@&1128840997581889586> <@&937047799441268746>
thx
i have a problem with one challenge on EC2
is there someone to help?
Do you have access to the #arte-general channel? If not you can configure your discord handle in the profile page in the hacktricks website and you will automatically be added to that channel
Hi guys!
@SoteriaSecurity is looking for a Senior Offensive Security Consultant (Cloud Pentester) valuing the HackTricks Training ARTE (AWS Red Team Expert) certification as a plus to access the role!
More info about the role in https://ats.rippling.com/en-GB/soteria/jobs/e6251998-dea0-41ab-a13e-e718e1591136
If your company is looking for Cloud Security engineers contact us and we will help you find them!
About the role As a senior member of Soteria’s Offensive Security team, you will be focused on leading and performing red team assessments,...
Anybody have experience with wix4? The example from the website is using the old wix3 https://book.hacktricks.xyz/windows-hardening/windows-local-privilege-escalation/create-msi-with-wix. I have wix4 working, able to do update info, icons, banner, add shortcut. I'm struggling to add a new dialog to install prompt for msi to have checkbox for desktop shortcut.
You might get a better response in #hacktricks
@modest elbow when are we getting ARTE/GRTE energy drinks?? 😂
Hahahaha that would be great
And why are you only arta-certified 😂😂😂
It’d be awesome merch! People could buy them prior to exam to get exam-passing superpowers! 🦸
We would love to create it. But we have no contacts to do so hahaha
Completely customizable drinks for any occasion using our online beverage builder. Not just a custom label! You choose ingredients, size and flavor in aluminum cans or bottles. We manufacture and ship to your door. Only 1 case (24 cans/bottles) minimum order. It's just Point Click Sip. Create your own.
Hahahaha I'll take a look and let you know
I got AWS Red Team Apprentice certificate 🤞
thanks for your support @modest elbow @jimmy
I just posted on LinkedIn and recommended amazing courses and labs to others
https://www.linkedin.com/posts/mohammadhosseinnamadi_aws-pentesting-hacktricks-activity-7228309612368658433-eGTJ?utm_source=share&utm_medium=member_desktop
Now is time for ARTE 😎
Just got an offer from Coalfire's AWS team! Couldn't have done it without @modest elbow, @glacial kelp and the HackTricks team!
ARTE definitely leveled me up to where I needed to be in order to crush their interviews!
Thanks for your words mate! Happy to have helped!!
Great!!!
Congratulations
Hahaha, I founded that team. Congratz!
A fun killchain that isn't talked about anywhere on Hacktricks is attack AppSync GQL. Lots of devs are lazy and directly inject the temporary API keys into javascript (AWS gives them a maximum life of a couple weeks to prevent this, but people do it anyway). The API key is always fully privileged, so all data is readable.
Less fruitful but just as fun is using Cognito credentials to reach into GQL. Fine grained access control for Cognito+AppSync GQL is really hard, and if they don't use AWS WAF to prevent introspection queries, you can read the entire schema and query whatever you want.
I built a tool a few years ago that makes exploitation pretty easy under the right circumstances: https://github.com/c6fc/countersync
That's awesome!! I don't know if you're still there! But I actually wasn't able to take that offer due it being kind of a low offer and also due to legal's extremely restrictive contract language but it's always cool to know that know that I got the chops now! ❤️
If you're doing the ARTE, put in a PR to HackTricks and you'll get extra credit!
Congrats
Coalfire has been paying less and less it seems
this is correct email to ask about student discount: training-support@hacktricks.xyz?
Yep
Thanks really appreciate this course. There’s is not much training like this out there and new fedramp guidelines require a red team but most people are not teaching cloud red team skills.
Thats exactly why we created it👌
what is the cost for lab extension?
Yeah I actually just breached an AWS environment and significantly escalated as a result of my training here!
It depends on the number of days you would like to purchase
Anyone aware of any configuration mapping tools similar to bloodhound/azurehound but for aws and gcp?
First GRTE Certified!. 🎉
Awesome GRTE journey, I recommend it to anyone interested on GCLOUD, you are not going to find nothing similar to the Hacktricks training course out there!.
Congratulations 👏👏
Congrats!!!
In GCP it's possible to find your permissions with the testIamPermissions API even if you don't have any permission!
Moreover, it doesn't generate any logs!
Find a PoC in https://github.com/carlospolop/Bruteforce-GCP-Permissions and learn this and many more GCP & Workspace hacking tricks in the GRTE certification: https://training.hacktricks.xyz/courses/grte
Next Friday Sept 13th is the last day of the GRTE (GCP Red Team Expert) early bird discount! Don't miss it!
Hey, If my labs are expiring and I extend the lab after it expires.Does it carry on the progress I made or it will reset?
Yes, you don’t lose your progress
great, thank you for the response @prisma raven
Your welcome 💪💪
dear sir
I have already purchased the GCP course, but can I study the course first and then start the experimental environment?
@prisma raven
Unfortunately no, both things start at the same time
No, sorry for not answering faster, heavy work day 🔥💀
60 days is more than enough
I was still having 25 days after passing the exam
So don’t worry
ok
thank
We're excited to tell you about Nuclei Templates release v10.0.0! This new version includes newly added Azure Config Review templates. In this blog post, we'll discuss automating azure cloud misconfiguration review, creating custom Azure checks, and sharing results on the PDCP Cloud for review.
Following our last release
Is there a channel for ARTE?
Yes, link your discord ID on the hacktricks training website
And you will be granted access
Got it I'm yet to take the course
Wanted some feedback on how deep do the modules go
I've got lot of mixed reviews online saying most of that content is out on youtube or that it is to basic :/
That’s fake 😂😂😂😂
Im pretty sure you won’t be finding nothing like ARTE anywhere else
Tell me what you want to know , I will answer your doubts
You can also check my post where I explained how it works
Starting from the basics deepen your expertise in AWS security with a comprehensive exploration of advanced concepts, including in-depth identity and access management strategies, encryption methods, sophisticated networking defenses and learn how to spot and exploit misconfigurations in more than 20 common AWS services. Master the application o...
Can I dm you?
Sure
2 new lessons about (ab)using GCP Cloud Scheduler and Workflows were released in GRTE certification (https://training.hacktricks.xyz/courses/grte)
If you already got access to it you can check them, if not, you can get access to the certification and will have access to all the updates in the future!
You can also take a glance to these GCP service from a offensive security perspective in:
@modest elbow and @glacial kelp you could have been rich: https://www.linkedin.com/posts/parisel_aws-vdp-vulnerability-disclosure-program-activity-7242113598800429056-Jpdr?utm_source=share&utm_medium=member_desktop
Saw it yesterday they finally have a VDP although it is not a bug bounty program so I guess they are still not paying for vulns?
Can be yes... maybe only diplomas XD
like NASA, PDF letters
probably...
BTW if you haven't read this one it is probably the scariest AWS vuln I've seen in the last couple of years https://engineering.doit.com/aws-transit-gateway-peering-exploit-a1715edd4c8a
Let´s see
luuul XD... how can Amazon fall in this stuff... Only front-end limitting privileges
after discovering this you always asks your self if someone has discovered before XD
You would think a service this critical would have been tested a lot more... I feel like any pentester would try this the first thing they would do when assessing this service
Yeah true I would
that´s why im saying...
"I wonder if I can connect to random on-prem environments!"
Did you know that setting arbitrary environment variables can get RCE in most scripting languages?
Some cloud services allow to modify env variables and you can:
Learn and practice these and other hacking techniques at http://training.hacktricks.xyz and http://cloud.hacktricks.xyz.
HackTricks Training
When are we gonna get HackTricks Prod Energy Drinks?
"Fuel Your Code. Break the Rules. HackTricks Prod—Power for the Bold."
🔥
Still need to look into that hahaha
It’d be cool for patreon supporters or something like that, or just as merch you can buy!
Do you have a patreon btw?
Interesting tool for fast checking in azure/microsoft stuff
HackTricks as the wiki has github sponsors
Yeah, for Azure there are a lot more tools than for all the other clouds (even together hahaha)
I can understand why
😅
Yeah this works really well too btw
Is anyone familiar with any vulnerabilities related to dce-rpc in azure ?
ARTE has been updated again!
Learn how to use and escalate privileges in Step Functions and put it into practice in the AWS Red Team Expert certification (https://training.hacktricks.xyz/courses/arte)
If you already pruchased the cert, you can access the new lesson!
You can also learn some Step Functions cool hacking tricks in https://cloud.hacktricks.xyz/pentesting-cloud/aws-security/aws-services/aws-stepfunctions-enum
🚨 New Course Alert! 🚨
Excited to introduce HACKTRICKS GRTA: GCP Red Team Apprentice, the perfect starting point for mastering security in GCP and Google Workspace (https://training.hacktricks.xyz/courses/grta).
👉 Learn about the GCP key services.
👉 Discover how to spot and exploit common misconfigurations.
👉 Increase your skills in hardening GCP environments.
To celebrate it we have reduced the prices of both ARTA and GRTA the following month!!
Hi there, how are you? If I want a sanity check on an ARTA flag, can I consult through this channel?
Hi @wraith canyon , you should go to #arte-general
If you dont have it, in the profile section of hacktricks training you can provide your discord username and you will be added!!
Thank you!
Anytime, you can also open a ticket for any further questions!!
hello all
I'm just curious
if i want to conduct a pentest on Azure and the client will create a user account for me to test with
which role should that iser account get assigned with?
maybe global reader? or is it something else?
I typically ask for multiple roles. Not just a single one.
Usually I'll ask for whatever the like standard RBAC roles that gets used when deploying new users to the environment, then I'll also ask for a Global Reader role so I can approach it as a greybox test.
Additionally, make sure that the client assigns you an O365 license and all that. It will increase the depth of the analysis you will get to perform.
I recently did a red team op where we could've done a whole bunch of cool stuff and demonstrated a lot of impact had we been assigned a 365 license to our assumed breach account likke everyone else had been
🔥
hello
how can i know how many days i have left for the lab
i got busy in the past week and didn't get the chance to study
Hi!! If you go to the dashboard, in the section "Your Labs", you should see how many days you have left for the laboratories of the courses you are taking.
Let me know if you find it!!
thanks for answering
but what if they don't have a default RBAC
Global Reader is ok to have
but is not enough to barely do things
what do you think is the suitable approach in this scenario
well with global reader, you can read teams/sharepoint
Felicitaciones por el tremendo trabajo que realizaron en los labs y en la metodologia. Sigo digeriendo el material aun y seguire por bastante mas tiempo. 👏👏👏
https://www.linkedin.com/feed/update/urn:li:activity:7249238712474099713/
passed CRTP, CRTO, PNPT, and OSCP in the last 2 months it's finally time for this baby
Hello, will the azure red team expert be available soon?
Around the end of this year or the beginning of the next!!!
Thanks a lot
🚨 GRTE Update & Discounts Alert! 🚨
We celebrate it with new discounts for GRTE. Go to our LinkedIn (https://www.linkedin.com/posts/hacktricks_grte-update-discounts-alert-we-activity-7254065963841576962-Lhio?utm_source=share&utm_medium=member_desktop) or Twitter (https://x.com/hacktricks_live/status/1848302265641173155) and learn how to get the discount!!
Our new lesson on how to abuse Google Workspace Sync is up now. Furthermore we have updated our Cloud Functions laboratories, learn how to escalate Cloud functions via storage monitoring here https://training.hacktricks.xyz/courses/grte.
If you’ve already purchased the cert, these lessons are waiting for you now!
You can also learn some Cloud Functions cool hacking tricks in https://cloud.hacktricks.xyz/pentesting-cloud/gcp-security/gcp-privilege-escalation/gcp-cloudfunctions-privesc and learn about Google workspace Sync in https://cloud.hacktricks.xyz/pentesting-cloud/workspace-security/gws-workspace-sync-attacks-gcpw-gcds-gps-directory-sync-with-ad-and-entraid
Hiya, Python security researcher here. Can someone reach out to me regarding an inquiry in the course content for GRTE when you have the opportunity? (Not a generic question, probably more line of business/abuse of platform related.)
Tell me
Shot ya' a DM Carlos. Cheers 😄
Did you send it already?
I did yes.
Might be stuck in your DM requests.
Hopefully it didn't go to Spam lol.
🎉 New HackTricks Bundles! 🎉
These bundles give you a 20% discount compared to getting each course on its own, so you get more for less!
1️⃣ Expert Bundle: Includes GRTE (GCP Red Team Expert) + ARTE (AWS Red Team Expert): Ideal for those ready to master advanced cloud security techniques in both AWS and GCP. (https://training.hacktricks.xyz/bundles#expert)
2️⃣ Apprentice Bundle: Includes GRTA (GCP Red Team Apprentice) + ARTA (AWS Red Team Apprentice): Perfect for beginners looking to build a strong foundation in cloud security. (https://training.hacktricks.xyz/bundles#apprentice)
Take advantage of this opportunity to boost your skills with a HackTricks bundle (https://training.hacktricks.xyz) !
Hello!
Does anyone else experience with training site issues?
Ah, it works now 🙂
How can I join the ARTE channel?
I am a student and got stuck
Hi!! Once logged in, you can yo to the profile section on top right of the page. There you should see a box that says "Discord handle (Optional)", you should fill it with your discord ID
You will be added automatically
Thanks, I did, but..I don't see the private channels
Weird should be right below this one
@glacial kelp Should it be already there right??
You have the role you should be able to see #arte-general
🔥 Black Friday Deals Are Here! 🔥
Until November 30th, take advantage of 30% OFF our Cloud Security Bundles and 20% OFF on individual courses with our Black Friday discount codes. Master advanced security tactics in AWS and GCP with our ARTE and GRTE certifications!
⏳ Don't miss out on these limited-time deals and start your journey with HackTricks today!
The discounts are applied automatically in the web http://training.hacktricks.xyz
@everyone In addition to the already mentioned Black Friday discounts we would like to offer a 20% discount in extra lab time until the 30th of Nov as some people requested!
Use the coupon BLACKFRIDAYLABS20 to get it!
Thanks for the discount offers. When can we expect to see the release of the Azure material?
we are working on it, ETA for the first Azure course is early 2025
Hi team, just quick question.
How long does hacktricks takes to respond on my emails regarding student discount as i need to buy the ARTE asap
Not much, why?
You can dm me!!
Hi all. I need a copy of my invoice for ARTE course. Can I request that through email (If so, which email address)? Thanks
Hi!! You can send us an email to training-support@hacktricks.xyz
Great! Thanks
I see I had actually sent an email to this address with this request a few weeks back and never received a response. I just sent another email now.
You should have received a response!
Got it! thanks for quick turnaround!
Anytime!
Are the labs in browser or do you create your own lab environment?
The labs are cloud based, you gain access to them, so you only need a computer/vm to install the tools needed to interact with the different clouds.
We set everything up for you. You just click a button and wait a bit for provisioning
Hello, sorry to bother you.
It seems that the azure training is scheduled for early 2025.
Will be there some early bird discount?
Hi!! Yes there will be an early bird discount
Thanks a lot, I intend to buy both the AWS and the azure course, but I have a limited budget.
I intend to buy the AWS course this year and Azure course next year if it's around the same price
⏳ Black Friday Deals Ending Soon!
This is your LAST chance to grab Black Friday deals on HackTricks Training. Until November 30th, take advantage of 30% OFF our Cloud Security Bundles and 20% OFF on individual courses with our Black Friday discounts. Master advanced security tactics in AWS and GCP with our ARTE and GRTE certifications!
🔥HURRY!!🔥
The discounts are applied automatically in the web http://training.hacktricks.xyz.
My GRTE lab hasn't been provisioned yet, can someone have a look into it. Its been 5 hours since I activated my voucher.
GCP modified an API just today in there was some labs that couldn't be provisioned. It's fixed already but you need to go to the labs page and reset the lab.
Sorry for the inconvenience
Is there a specific labs page, the only page I see is https://training.hacktricks.xyz/dashboard
Here on the "continue where you left"
The labs start in the part 2!
I get an empty page when I try to access part 2
Weird i can access with no issue, can you try other browser?
ok, let me try chrome
same thing in chrome
@glacial kelp @modest elbow Can you take a look to this?
Look dm!!
Hey @glad orbit I think you should be good to go now. GCP made a change yesterday and yours was 1 of the 2 deployments that failed because of this. I missed that it happened twice and only retried for the other student. Sorry about the delay
Thanks @glacial kelp, I am able to access now
By the way if you add your discord handle in the profile section of the website you will be added to some private channels and a support ticket system
thanks @glacial kelp , I added my handle to https://training.hacktricks.xyz/profile
Hi there! I keep getting this error message, I'd like to purchase this before the deal ends
Hi! It was until midnight EU time.
However we just extended it until the 2nd of December till 23:59 GMT+1!!
Don't miss it❗
Can I get access to the private channel?
Any updates on when the AzRTE is coming out?
Also, @glacial kelp I never got my GRTE badge
Added you to the role
It is a shame you have to choose between what can to show in discord
We are aiming for February, but there is a lot of research left to do
Thanks a lot! Now I got it. By the way, I can send the voucher again at any time, is that correct? Even if the first voucher link expires
I dont understand the question 😅
I received this after purchasing the course.
However, I assume I can use this option to get a new activation link at any time
Hi! I think you will get the same activation link with that button. The vouchers is expected to be used in 1 year from the time it's purchased (note you have un 1 Dec 2025). However, if you want to activate it later let us know
I have a couple of questions, can you add me to the private channel
YOu should see the #arte-general channel
I see it now, I am working on GRTE, can you add me to that specific channel
oh sorry #grte-general
Thanks, I see it now
Great
Howdy @modest elbow or anyone that can help.
I am doing the ARTE and am stuck on 2.13 ECR - Elastic Container Registry 2nd Lab - Push Docker Image.
I downloaded the walkthrough but still cannot get it to work.
When I run the lambda invoke command I get the following error in the out.txt file:
{"errorType":"Runtime.InvalidEntrypoint","errorMessage":"RequestId: 0f86b30a-b562-4235-bac1-61ce7e19ad0c Error: fork/exec /lambda-entrypoint.sh: exec format error"}
Howdy @carlospolop or anyone that can
Hi, please open a ticket so I can help you
How do I open a ticket
go to #training-support
I dont have access
Did you added your discord id to your profile in hacktricks training?
I'll do that now
Hey there, I am thinking to get 15 days lab extension for ARTA course. But if I am able to finish all the labs in the allocated time that I have left and if I did not redeem the voucher for lab extension (I am guessing everything on this platform is based vouchers), can I then issue an refund for this unused voucher?
If its being more than a month, and of course it has not being used yes.
But note that a 2% percent of the transaction will not be refunded, because of Stripe fees
Okay 👍
Looking forward to it my dude
Me too 😂
creds are fine, anyone has same output for kms:PutKeyPolicy (I reset lab, same thing)
other labs ok
I ran --debug also, but doesnt seem to be issue on my end - could someone help please
Open a ticket
ok
Hi all 🙂 Is this the right channel to ask for hints about ARTE labs? I think my instance of "API Gateway Sign Request" may be faulty
Is the #arte-general general one
You have to add your discrod name to the hacktricks-training profile
Awesome thanks - just added 🙂
You should see the channel now!
Is there any way to invoke Lambda function without the Invoke permissions?
I noticed the lambda:UpdateFunctionConfiguration privilege escalation via env variables but is it enough just to set them or do I need to invoke the function anyway?
You need the Invoke permission to invoke it yes
Im not aware of any other way of doing it
But there can be some triggers, right? like uploading something to S3 bucket ?
Yes there could be triggers
Also if the lambda is exposed via URL and everyone is allowed to acces the URL it's a way to "invoke" it
I added GCP and AWS Red Team Apprentice Courses to the Cloud Security Fundamentals section of https://learntocloud.guide a few weeks ago.
GitHub license
Thanks!
Hi @everyone !
We are releasing the HackTricks assistant chatbot https://www.hacktricks.ai/ for free!
This chatbot has access to HackTricks & HackTricks Cloud knowledge base so you can ask it questions about topics discussed in HackTricks or cybersecurity in general and it'll be able to help you using HackTricks knowledge.
Moreover, it also allows to generate interesting facts and questions about the selected HackTricks topic or even about a specific certification. This allows you to practice hacking (from a theoretical way) from anywhere and prepare for the top certs!
Chat with HackTricks Assistant and prepare for several certifications.
Cool
Might have been a temporary vercel breakdown, its working now
I still can't access it.
? I can access it without any problems
And a couple of guys I asked also can.
You get that error always?
I was able to access the website using a VPN. After disconnecting the VPN, I can still access it. However, browsers that have never accessed the site using a VPN cannot reach it.
By the way, I am currently in Taiwan.
Yes, I accesed vercel to see the logs and openai is returning some 403 because of the location of some used vercel servers. I'm trying to update the configuration to only use vercel servers from the US
could you try again and let me know?
new deployment, could you try again?
shit, ok, I'll take a look these days but for the moment I guess you need to keep using the VPN
guys i got an announcement of a pentest AI assistant bot
how to access it ?
think it was from this server, if i remember correctly
been using chatgtp some time and its quite alright for brainstorming
how would this compare?
This is like chatgpt with further access to hacktricks data with an interface prepared to learn about hacktricks content and prepare for other certs with questions related to them
This is great
Probably less chance to hallucinations then since hacktricks data is awesome
Even in polish it has good flow when I am testing it :d
Hi @everyone ! Happy Sunday!
As requested by some users, the mobile version of the web is up now.
Just access www.hacktricks.ai from your phone and test yourself about hacking topics anywhere!
Works great !
Not related to this training but pretty interesting resource https://comparecloud.in/
A simple cloud comparison chart of all the cloud services offered by the major public cloud vendors globally.
Hey thanks for sharing. @south wave
Hi! I don't know if it's proper channel to ask, but: has anyone run into issues with the ARTA SQS lab? Could you walk me through the correct way to retrieve the output after injecting commands into the vulnerable Lambda function? I’ve tried several approaches and still can’t figure it out. Thanks in advance! 😉
hi!! do you see the #arte-general channel?
looks like I don't have access there
Did you put your discors id into the hacktricks trainning account?
no, I'll do it in a minute - thank You!
nice resource, it allows to filter extensions for free, unlike greyhatbuckets > https://osint.sh/buckets/
Hi everyone, would someone from support be so kind and add me to the gcp channel ? Thank you in advance ps. yes i added my discord id on my profile
Hi, do you see the #grte-general channel??
hi @near prairie , thanks for reaching out. no unfortunately not.
You should have it now @molten vortex
Thank you @near prairie
@everyone Learn cloud Hacking from 0 to Hero in 3 days!
The 3 days-3 clouds course is back at RootedCON: https://www.rootedcon.com/trainings-rooted2025/
Learn AWS, Azure and GCP security in 3 intense days with 3 expert cloud hacking instructors in this amazing course (in Spanish)!
Not available in English too?
Azure course has been released?
It'll be available in english at HackSpaceCon in May, for the moment this is course we only deliver in person
not in the training platform, still working on the labs but we will give news soon!
Any plans for this in English, but in Europe?
We give also to companies interested that reach us, but we don't haven't look for any other conference in EU yet
Hi, I'm thinking about buying a voucher for the courses, but before doing so, want to check one thing. Is there any expiration for the certifications, or are they valid indefinetly?
No, there is no expiration for the certification!
Thank you!
I passed Google's Cloud Security Professional Engineer Exam last night and I attribute most of my success to actually taking the GRTE Hacktricks Course: https://hackidle.com/Course+%26+Certification+Reviews/Google+Cloud+Certified+Professional+Cloud+Security+Engineer
I really just had to fill in a few personal gaps in key management
That is really interesting I'll read the blog post more in depth curious to see how the two certs compare as the have slightly different angles
@everyone we are super excited to share with you that AzRTE (Azure Red Team Expert) is now in pre-release with the early bird discount applied! Don't lose the opportunity to get it at the best price.
Get ready to improve your Azure & EntraID hacking skills!
More info in https://training.hacktricks.xyz/courses/azrte
Signing up now! [or well, one of my guys are] ... great to see this coming out, we have been waiting with bated breath 😄
Will it be possible to gain access to the course material prior to the 29 March ?
Unfortunately no, March 29th will be the first day to access the material.
thanks for the update, we will look forward to starting, payment has been processed now 🙂
Awesome!!
Pls I have html script am looking for the php who can help out
I honestly read AzERTY (which is like the qwerty of french keyboard layouts) when I said the message out loud
when is the kubernetes course coming out? @modest elbow
Atm it's available on-premise for conferences and companies. For Hacktricks Training platform we will work on it after the Azure one is finished
got it
Another question, is microsoft grapth api mention in any of this chapters from the new azrte?
I assuming that tokens & API could covered it
Google de-indexed it some time ago now we use https://book.hacktricks.wiki/en/index.html, and https://cloud.hacktricks.wiki/en/index.html
Yes it will be covered in the tokens & Api lesson
In AzRTE we will talk a lot about EntraID and its APIs
And you will be using it in the labs too
Would ARTE help with Security Engineering?
If what you do relates to aws I would say yes. Although it is more tailored towards attacking aws more than defending
Does the GRTE course have any training on "Apigee X" ?
Please use the #arte-general channel for these questions, or the ticket system
I struggled a while with the signup form to create an account for the new azrte training.
It says 8 to 32 chars. But it's actually **24chars **max, it won't accept passwords of 25chars or longer
My advice would be either allow up to 32 chars or change the error msg. It's a bit outdated though, why not accept 40 chars passwords e.g.?
I'll take a look at why it is limiting at 32, y can increase it to 64 but will keep a limit as not having a limit can end in long delays calculating hashes which can impact performance
Yeah, so it's limiting at 24 now, but I think that's what you meant.
Yes sorry, I'll check in a bit
You should be able to use up to 64 char passwords now
Let´s get ready to rumbleeeee 😎
Yeaaahhh
Hi guys, not sure if it's the proper channel...
I'm a little blocked in the EC2 lab from ARTA...
I did the SSRF, i got two roles, the one listing the secrets is not allowed to read them...
So, after trying this and that, and re-readig the materials a couple of times I'm lost...
I also tried to privesc based in the roles I found but I couldn't move forward from that...
lab 1
@modest elbow
you can add yourname bong into the hacktricks profile which will give you a hidden channel for ARTE-general or ARTA-general . I am not sure for ARTA as i enrolled for ARTE
Please, do as @jovial hamlet said to be able to ask in the right channel and to open private support tickets
thanks!
Hi folks, general question:
It's not yet clear for me whether Cloud attacks are post-exploitation/pivot or we can target the cloud gathering the organization ID or even with no credentials ??
You can gather info without credentials (unauth enumeration) and in some services exploit misconfigurations that might have. About post-exploitation is usually when you have some kind of access already and you can change certain things/configurations inside the organization.
thanks Jim, i see... then it's clear to me now that it's possible to perform unauth tests against the cloud... but the "how-to" is not yet fully 100% clear... should I gather target information, as a "must-have" element, or I as the pentester might have my own cloud user/org to perform the test?
coz in my mind there're 2 possible scenarios: my-creds (kind of "cross env" testing), or no-creds.
So, both scenarios test for publicly available resources, but i wonder if behind the scenes, the cli/cloud requires some such of creds being loaded, or the tests on the publicly available services won't fail when there's someone testing without creds... ??
the "technical" part is not yet fully clear...
So you are wondering how to perform a blackbox approach, right?
Well... correct me if I'm wrong: black-box test means no previous intel/knowledge of the target (surface included).
I would like to know just a smaller detail: how the unauth test is performed, should i use my creds (kind of "cross env" testing), or no creds are needed?
Now i get the question, ill answer in the arte channel or in DM whatever you prefer
ARTE might be better in case someone like to add something 😋
Bought it today as well! Will be activiating after March 29, and can't wait to dive into it!
Niiiceee
Lets go for first blood 😎
hahahahahahaha
we are all ready
Glory for everyone, we fight the same battle
🫡
Hi all! Happy Friday! Hope you enjoy your weekend!
@glacial kelp @near prairie can i buy the voucher and activate in 3 month?
Yes, you have one year to use it, starting on the 29th of February
Got it
Of march *
Yes March😅
oh lol my bad lol - it's here: https://hackidle.com/Course+%26+Certification+Reviews/Google+Cloud+Certified+Professional+Cloud+Security+Engineer+Review
AWSCompromisedKeyQuarantineV2 (v3 was released during the creation of this article) is an AWS policy that attaches to identities whose credentials are leaked. It denies access to certain actions, applied by the AWS team in the event that an IAM user's credentials have been compromised or exposed publicly. The blog article will dive into the many...
This is interesting
Didn’t know about it
Have you ever found it applied in real assessments? @modest elbow @glacial kelp
Im curious now
Never seen this
Hi there! Is there a timeline on when the AzRTA course will be available?
Probably a couple months or so after AzRTE
Oh its much longer than I thought🤣 Looking forward to it!
Go for AzRTE! Let´s tryhard
I'll definitely go for it! Just want to take steady steps lol
Hi @everyone ! To celebrate the Azure Red Team Expert certification is released in a week we are going to launch the first Cloud PEASS!
Welcome Azure PEASS (https://github.com/carlospolop/cloudpeass), a script that can get a management and/or a graph token and find ALL your permissions inside Azure resources and Entra ID. Moreover, it'll use Cloud Hacktricks (https://cloud.hacktricks.wiki/en/index.html) and HackTricksAI (https://www.hacktricks.ai/) to color the sensitive permissions you have and even tell you how to (ab)use them!
This is just the first of the 3 initial Cloud PEASS to be released with HackTricksAI support for red teams!
Chat with HackTricks Assistant and prepare for several certifications.
Hello, who is/are the authors of the AZRTE course please?
Hi! The HackTricks Training team, Ignacio, Jaime and Carlos
Thank you
After AZRTE purchase, can I enable it whenever it fits my schedule?
Yes, you have 1 year to enable it whenever you want
Thanks a lot
Thank you!
Does the course cover hybrid scenarios?
It will cover AD <--> EntraID scenarios, but this the only lesson that won't be released tomorrow as we are still developing the labs
ok, I understand
@everyone the new AzRTE (Azure Red Team Expert) certification is up and running!
If you have a voucher you can redeem it from today!
If you don't, get one while the early bird discount lasts (only a couple weeks more left!)
And so it shall be!
Hey carlos make a complete web hacking frow intermediate to enterprise level in video form
If you can't then help me about your wiki pages
I am confused
Does those content about web is enough for bug bounty and entry level jobs?
for entry jobs despite of "know" vulnerabilities you have to have some basic of app developing, networking, scripting and so one. Most of companies form my experience looking for people which could learn fast, have analytic mindset got basic knowledge which will be valuable during problem resolution. No one looking for guy who could from memory describe all owasp top 10 vulnerabilities
This is just describing me
so if you got a match not be worried to try 😄 job interviews are not hard like most people thinking
Main thing is my english language is weak and and am still learning computer language 🥲, communication skill is literally 0
Is there anyone looking for developer?
Now I am actively looking for a new job opportunity or task, and here, I'd like to connect with you. Thank you.
Hello, I don't know it this is the right channel but I'm stucked on SSRF lab, on ARTA.
Hi, no, go to #arte-general or open a ticket with #training-support
Appear as No Access.
Add your discrod handle to your account in hactricks training
Then it should appear automatically
hellooo, I have been researching recently about device flow authentication, and discovered in a yt video that is supported by Az Cli, what didn´t expect as Az Cli can´t be configured with access tokens, I might take a look on how it´s managing the connection, cause maybe something can be done in order to make it work with Access/refresh tokens
At the end of the day that´s what you get when device login, a FOCI refresh/access token
Hi @everyone !
AzRTE (Azure Red Team Expert) early bird discount will be gone on April 25th. Learn Azure and Entra ID hacking with tens of hands-on labs to practice at the best price while it lasts at https://training.hacktricks.xyz/courses/azrte
Moreover, if you prefer to learn on a live training check out the 2 days 2 clouds course we offer at HackSpaceCon in https://www.hackspacecon.com/HackSpaceCon#/awsazurehacking and learn AWS and Azure hacking in 2 days!
Pfeww i'm getting the payment on the 24th. Right on time!
☁️ I'm releasing a new tool: Cloud Detective
🌐 Lately, I’ve been getting more involved with cloud stuff, and one thing that quickly stood out is that whether it’s an external audit or a red team engagement, we almost always end up with a pretty big list of subdomains after the OSINT/Recon phase.
The next logical step? Scanning for ...
Thanks everyone for the support, don´t know why but the tool is getting too much love ❤️
Hello. In ARTA KMS Lab any ideas?
An error occurred (InvalidCiphertextException) when calling the Decrypt operation:
aws kms decrypt --ciphertext-blob ms_lab_1_user2_credentials_encrypted.txt --key-id 32778d35-462d-4bf6-b62d-f2c6eb043bbe --profile audit01 --region us-east-1 --output text --query Plaintext | base64 --decode
i removed whitespaces in the base64 encrypted key file already
i used file://enc.txt and fileb://enc.txt
nothing working
file should work as its textmode
Hi @leaden patio, please, in the training web go to your settings and set your discord hadle. Then, you will be invited to other training private channels were you will be able to get support and also open tickets!
It's automatic, note that you id is "p3rpl3x_x25"
ok solved both problems
is the hacktricks training dashboard not loading for anyone else?
i’m not able to access my courses
Its working for me
Working for me too.
Try removing te cache
tried that, tried switching browsers, tried on my phone
just getting a blank screen
maybe something’s wrong with my account
You should not have any issues, in any case @glacial kelp can you take a look to this?
I'll DM you to troubleshoot the issue
Has this been shared yet and did anyone get around the test it out? https://github.com/FalconForceTeam/dAWShund
https://www.hacktricks.ai/
Could you please open it?
Chat with HackTricks Assistant and prepare for several certifications.
Its working for me
few days back there some discounted offer for gcp course right? is it still valid?
@modest elbow
Last one I think that was in Black Friday. But we always have discounts for students and bulk purchases, what do you need?
let me ask my boss il get back!
Hey, I bought ARTE last June. But I didn't activate the voucher. I'm going through a busy period. Is there a deadline to enable it? Or can I enable it whenever I want?
It is one year after purchase to activate the voucher but if you can't start it yet message us at our support email and we'll help you out
Hey everyone,
I have a couple of questions about the ARTE certification.
In the FAQ section, it says:
"The voucher will grant you 60 days to complete the laboratories. However, you will be able to purchase laboratory extensions if you need them."
60 days in my opinion is more then enough i finish all in 30 days
Hi!
Most of the students dont need the extra days to finish the course, but in case that you need it to extend it, the 30 days extension is 259€.
Regarding the digital badge, no, for the moment we just issue the PDF.
Let us know if you have more questions!
I just started the ARTA training. I deployed my first lab and was able to configure the CLI. When I deploy my lab again, will it generate new keys that I need to update my CLI profile with?
Hi! Yes it will give you new credentiasl to use for the lab, and update your config credentials file!
Great, thanks!
For this questions you can use the #arte-general channel, do you see it?
Yes, I wasn't sure since I am doing the ARTA 🙂
@everyone
🚨 New HackTricks Training Lab Discounts Now Available!
We’re excited to announce new discounts on HackTricks Training Lab extensions!
When you purchase a new certification, you can now purchase at the same moment a lab extension with great discounts.
🎁 Bonus: This week only, these discounts are automatically applied to users who have already purchased a certification. No action needed!
Nice
If we buy them do they immediately activate or can we activate them later?
You can activate them whenever you want
Awesome, thanks 🙏
Hi guys.I’m thinking of signing up for the arte course — just wondering, is it possible to get an invoice for the payment? I’ll need it for company reimbursement.
Would really appreciate any info!
When buying the cert from the web page with card you can add your company details and the invoice will be automatically generated with those details.
If you prefer to pay via bank transfer send us a message with your company details to training-support@hacktricks.xyz and we will generate you an invoice
I see
thank you all!!
Hi, I want to ask if I purchase the 30 days extension to my aws expert course, do I have to use it just after my 60 days (which come with purchase of course) expires or I can use the 30 days extension voucher later at any time even when my 60 days of lab expires. Thanks 😊
You can activate the voucher at any time in the next year from the day of purchase
@modest elbow Hi Carlos! How does it work with ARTE again? Does the lab time automatically start when I buy the course and enroll into the course? Or can I take my time watching the videos and reading the PDF, and then start the lab access after a month or so? Can the lab time be paused?
Hi, the lab time and course starts once the voucher you receive, after you buy it, is redeemed (you have 2 years to activate it). Both the course and the lab time start at the same time so you dont have extra time to watch the videos. Unfortunately, the lab time can not be paused.
ok, good to know, thank you very much!
Let us know if you have more questions!
Hi @everyone !
We have just launched the new AzRTA (Azure Red Team Apprentice) certification in https://training.hacktricks.xyz/courses/azrta
Take a look and let us know if you have any questions!
Hello
thank you
Tenable Cloud Research discovered a supply chain compromise vulnerability in Google's Gerrit code-collaboration platform which we dubbed GerriScary. GerriScary allowed unauthorized code submission to at least 18 Google projects including ChromiumOS (CVE-2025-1568), Chromium, Dart and Bazel, which are now remediated. Third-party organizations tha...
Hi all, it seems GRTA is a subset of GRTE. So taking GRTA with intention to the take GRTE is not recommended, right? (Because also there seems to be no discount if you have the apprentice course)
If you have some cybersecurity background but no red team what do you suggest to take?
Thanks to everyone that read until here!
Hi! Yes GRTA is subset of GRTE. We recommend to directly take the GRTE course as it has more content and its more complete. Dont worry about having no red team background GRTE starts from the basics and you wont have any issues (There is also the support channel that can help you). And in case you end up getting GRTA, you get a 20% discount after finishing it for the GRTE course.
Let us know if you have any other questions!!
Thanks for the fast reply, so money wise is not advisable to start with the apprentice if you're wanting to go for the Expert as well, based also on the overlap.
Is it still 60 days of access since the redeem of the voucher?
What do you need for the student discount? Email account from a student email? Thanks again!!
Yes, once you redeem the voucher you have 60 days of lab access in GRTE. (GRTA is 30 days). For the student discount write to training-support@hacktricks.xyz with your uni email.
Thanks again, much appreciated
Hi guys 👋, I see you have next meetup in Valencia, Spain
Rooted Valencia, 25–26 de septiembre 2025
Is it possible to register for the event now?
In general, do you have some other resources where people do similar meetings in Spain, especially in Valencia
Thanks🙌
@everyone check the HackTricks Training discounts for the Summer!
https://www.linkedin.com/feed/update/urn:li:activity:7346175851421433856/?actorCompanyId=72119507
This summer, learn Cloud Security!
Use the code SUMMER to get 20% off in all certs before August 1st.
Also repost, tag a friend and have him tag you back and you could both win a voucher for the AzRTA cert by July 10th!
#hacktricks #training #cloud #hacking #security #aws #gcp #azure | 41 comments on LinkedIn
Code is not applicable to bundles?
No, just to lab extensions, and individial courses
Hi, has the raffle for the coupons been held?
Hi! Yes, we've published a comment in the post with the winners
Does the ARTE course prepare you for a real world Red Team Simulation? Are stealthy methods and attack paths outlined?
Yes, Red Teaming and Whitebox review are the main goals of this certification. After learning the basics every lesson contains a section about attack paths per service, and also post exploitation and persistence techniques per service.
Then, in the blackbox lesson you learn more red team like tricks + you have 3 labs simulating red team exercises.
Finally the exam is actually a red team simulation
yep, it does feel very Red Team althgouth doing azrte 🙂 its good one sometimes too good ha
if I buy in bundle, can I buy the course first and lab later 🥲
Unfortunatelly no, once you start a course the lab time starts too
That means I can't buy course separately 😦
No, you need to buy the full certification, with all the content and lab days included. If you run out of lab time, you can buy extensions for it
I mean like, in bundle, I only see course price, not lab price, so, I was asking about that
The lab time is included in the course
You buy for example an ARTE and a AzRTE you get the course and 60 days of labs for each one of the certs
And if the lab time that is included is not enough you can buy extra time
Let us know if you have other questions or if it is not clear!
okay
When the course bundles are purchased you will receive vouchers. These vouchers are then redeemed (when you decide) which starts your lab/course time.
The vouchers last for a year, I think? Essentially it lets you set your pace of owning all courses but taking them at your leisure
yeah, and they last 2 years by default (or if anyone expires you can ask us and we will give you a valid one)
Thank you, that's a relief to hear
Hi @everyone
Last 7 days for the SUMMER discount of HackTricks Training!
Una vez adquirido el voucher puedo iniciar el curso la fecha que yo quiera?
Si, tienes dos años para usarlo, aunque se puede ampliar sin problema alguno
Hi @near prairie how many flags are required to pass the GRTE exam totally.. I heard there are 3 flags to find. ...? What are the ways to get Certified
Hi! Yes it is a 12 hour exam and you need the 3 flags to pass. It is the only way to get certified.
However, if you do a PR to the Cloud Hacktricks book with new Privilege Escalation methods of the cloud you can pass the exam with 2 flags, but it needs to be a new one!
@everyone last day of the summer discount! If you want to get some discounted certs or lab extensions use the SUMMER code today!
If you could only get one, (and have none yet), which one would you get - and take advantage of the sale?
I would say ARTE as it is the most widely used cloud platform, if not AzRTE is a good option too.
Unless you want to specialice in google cloud, ARTE or AzRTE are the best options.
(My personal favorite is ARTE)
Nice! I'm not surprised. I'm a little behind in cloud stuff, but have my eye on these certs!
Also AWS is the simpler one to start and use I would say, the concepts are easy to get and is not as intricate as Azure for example.
Thanks for that perspective. I’m definitely kind of a noob when it comes to cloud stuff, but I’ve been around the block with traditional IT stuff.
I’ve been putting it off for a while now, but I have come to the realization that I can’t avoid it forever
Let is know if you have more questions!!
I really appreciate it.
Modified queries for bloodhound CE in order to easy query for Owned objects on Onprem-AD -> Entra/Azure, as the default ones doesn't filter owned objects, which are the most interesting ones most of the times.
Hi admin, with mandatory enforcement on MFA on Azure logins, does that affects the existing labs in Azure apprantice/expert courses ?
Yes, it will affect a small number of labs, we will add MFA into those labs when the time comes so they continue working
is the training site down ?
Trying it for few minutes now.
for me is working fine, is it already working for you?
yep its working now thanks 🙂
We don't use azure for the website so not sure what your browser was doing 😂
I noticed the AzRTE course curriculum doesn’t really cover concepts like lateral movement, persistence, or evasion that are usually tied to red teaming. Just curious, is there a reason for that given the cert is called Azure Red Team Expert?
Not an admin, but every course covers these concepts
The syllabus indicates from a very high level the services that are going to be used in the course.
Inside those services you will learn how they work and then how to (ab)use them (privesc, post exploitation & lateral movement and persistence).
Then we have specific blackbox sections to talk about other common red team attacks (among them AD <--> EntraID pivoting and in the final section we talk about azure defense services and how to try to bypass them
So I think the certification covers all those things
Gotcha. Thanks for the clarification.
Np! If you need more info feel free to ask here or check also https://www.youtube.com/watch?v=CBQl7Kvlu-U
Presenting the new HackTricks training Azure Red Team Expert (htAzRTE) certification by HackTricks Training.
The most complete certification to learn about hacking in Azure and Entra ID.
Check more info in https://training.hacktricks.xyz/courses/azrte
Sure
Is the training site down by any chance?
Are you still having issues? It works fine for me
I can’t access it yet, is there any geolocation restriction? I can visit the normal site for attacks info, but I don’t reach the training subdomain
@glacial kelp Can you take alook?
Last time I visited the training site was 3 weeks ago, and it was working fine for me
We don't have any geolocation restrictions
Is there any kind of content filtering on your side like from a work related proxy or something?
Remember they are in different domains now.
Training in: training.hacktricks.xyz
Book in: book.hacktricks.wiki
Correct, I can’t access the first one 😢
We dont have any restrictions as mentioned previously
Maybe is your ISP restricting the address
Maybe try adding the IP of the site to your /etc/hosts manually and see if you can visit it
can we pin this?
Vouchers expire after a year from the date of purchase, correct?
Hi! No they expire after 2 years!
@near prairie @modest elbow ^ also posted in several other channels
Thanks!!
Who could i speak with regarding purchasing a bundle for a team of 6-8 for GCP/AWS trainings?
We received your email, we will answer it asap!
Are you guys moving to a new domain for the training website? Stumbled upon this on google, and thought the domain looked different than normal.
https://hacktricks-training.com/
Registered 3 days ago. Just wanna make sure noone is trying to create a phishing site
Modern, responsive Next.js frontend for the Hacktricks Training platform
Hi! Yes we are planning to! But it is not ready still
We will make an announcement when its ready!
Alright perfect, it's looking good!
Yes, you receive a voucher for each course, and you have 2 years to use them
alright thank you, Imma think hard about it
Any questions let me know!
@everyone Black Friday Month is here! — and so are our biggest HackTricks Training discounts of the year:
• 20% OFF all Courses
• 15% OFF Lab Extensions and Exam Retake Vouchers
• Additional 10% OFF all Bundles
→ That means 25% for 2 courses and 35% for 3 courses.
One discount code per transaction. Offers valid from Nov 1 to Nov 30 .
Discounts already applied at https://training.hacktricks.xyz/
HackTricks Training
Wonderful thanks!
Hey @near prairie is the whitebox for the apprentice course the same as the whitebox for the expert course?
One lab, yes is the same. But in the expert there is another extra lab
Thank you Hacktricks Team for such an awesome experience, really appreciate all of the help and support for the community and staff. The effort put into the labs is fantastic. A lot of valuable course content and practical examples of how to abuse mis-configurations.
Thank you @near prairie especially for always assisting with my bombardment of tickets.
Congrats on all the work mate! Cloud Expert Certified is not an easy one!
Nice Job!!! And always a pleasure!🫡
I'd like to ask if the exam requires a passport and webcam like OSCP?
Hi! No it does not!
Thanks🫡
Anytime!
Greetings house , please who know how to do redirecting of domain for long lasting
Hello, if I completed the ARTA course and want to take the ARTE course, will the labs I completed at ARTA count or do I start from scratch?
@barren viper Hi, if you already completed ARTA you will have no problem starting from the beginning. In fact, that would be my advise so you can see if there is any additional information on the topics that u saw in ARTA course. If you ask for the flag progress im not sure maybe just someone else who has your prev situation or a moderator could answer if the ARTA flag progress counts for ARTE
You will need to redo the labs you did in ARTA in ARTE
Okay, thank you.
Hi! My voucher for ARTE course is expiring 14.11, but I had a plan to activate it on 17th of November. How can I do it?
Hi! No worries DM me or open a ticket!
Done
i have done all of my walkthrough , and got stuck and i want to learn the exact way.. and not to waste time.. can i somehow get more walkthroughs?
I've just seen your ticket ill answer there, but sure we will give you some more!
Stupid question, I've booted my lab up in the ARTA course and have no idea how to access it
Hi! Please use our #arte-general channel for question related to the certifications
Add the discord handle to the profile area in hacktricks training
Now what did you do until now?
I've added my handle
Awesome now you should be able to see the course channel!
Do you manage to access?
Yeah, got it thanks
Hi! I am currently preparing for my ARTE exam and thought about getting the other two expert courses too. When reading through the FAQ, I noticed, that the access to the course content after validating the voucher has been limited to just one year? When did this happen? 🙁
Due to potential compliance issues and some cases of account misuse, we’ve had to make that change in the FAQs. However, no access is being limited at this time, and we currently have no intention of restricting it.
What do you think guys? 🤣
A lot of hate on AWS lately
well I can definitely agree that you don't need to make MVP complex, but you can still use public cloud like AWS or GCP as simple VPS (also you can get the small boxes for free instead paying the 5€ for VPS somewhere else) - IMO if you have more micro services than paid users you are doing it wrong!
Tbh I remember that when I started with AWS I found it pretty complicated to understand. Then I realized that thanks to this AWS is not as vulnerable by default as other clouds (although I agree that several AWS services could be simplified a lot without loosing any features or maing them more vulnerable)
AWS is easy to take down if you know where the first data center is….and some tricks from an old hat from the hatter
Hopefully they learned their lesson….but I doubt it
DNS and cloudflare have been taking some hits lately, they think A.I will do all the work for them when really they should be looking for people who actually know what the hell they are doing
Hello, I would like to start the AWS Red team expert course, I have.some understanding of cloud computing, I.was wondering if I should take an AWS course before starting this course?
In my opinion and from another person I know who took it, you can start from zero knowledge on these.
Obviously having some prior experience helps but is not required is my perspective
Thanks a lot
yeah, personally I don't love the aws certs (back when I took them in like ~2018). Not very hands on or technical up to the solutions architect/security specialty level. Felt more like sales training than education haha. I'm maybe 75-80% done with the course, and i think you'd get more value from ARTE + experimenting on your own if your goal is any security discipline.
@everyone this is the last week of the Black Friday discounts! Check them in training.hacktricks.xyz
@modest elbow Hi there, after I purchase the voucher, when will it be expired, if I do not claim it ?
I am planning to buy bundle but i cannot do all at 1 go. I can only do in sequential when time permits.
The vouchers have a 2 years expiration date, in any case if the time runs out we can provide another one so you can finish the courses!
So dont worry about it!
Hi @near prairie 24 I can't extend my lab time for some reason.
Open a ticket or use the private channels for these issues!!!
Write me the error you get
Done
The discount ended yesterday
Wow! I thought it’s until the end of Nov 30.
Hi! Write to us to our email training-support@hacktricks.xyz, or DM me!
@near prairie Sir sorry for ping, but just a question. Let's imagine the situation.
I have GCP cloud and have service account credentials, i've listed organizations and projects and in one project i've been found service account over which i have roles/iam.serviceAccountTokenCreator . Then the service account i can impersonate has permissions on the function
I described the function and find where GCP stored the zip archive with function's source code, but i can't list bucket policies using
gcloud storage buckets get-iam-policy gs://bucket_name
is it correct that i have to try list or download the zip archieve with the function's source code (from both account) to understand what the function does and the invoke it if it will be usefull
Absolutely, if you can’t view the bucket’s IAM policy, then yes, your best move is simply to try downloading the function’s source archive, take into account you will need storage.objects.get permission to do that.
Other option would be trying to bruteforce the bucket name, in case the bucket is publicly open, however this usually is unlikely.
and is it the good way to find who has it, cause in gcp as i know u have to list everything step by step (and it takes a bit longer than in AWS)
cause i verified it using
gcloud storage objects describe gs://bucketame/function.zip
and if i see the output so i have storage.objects.get permission
You can also try using the list command (storage.objects.list) gsutil ls in a bucket. But yes try that too!
@everyone All the videos in the Hacktricks Training courses, now include subtitles in multiple languages. These captions include the languages showed in the screenshot and many more!
Enjoy the content!!
In blackbox lab 1, I reached the point where ||I have the user blackbox-lab-1-user-2, added that user to the group, but bruteforcing the permissions gives the exact same permissions I had before adding to the group. (I bruteforced with both bf-aws-permissions and the simulate scripts). Did I miss the first flag at some point?||
You should be able to read the flag now
thanks, my bruteforce scope was a little narrow I guess
Hi, I need to open a support ticket. I’m having a problem with ARTE Labs. Where can I do that?
You can open a ticket in #training-support channel
Is https://training.hacktricks.xyz/ ssl broken?
HackTricks Training
it works properly in all my browsers
Ok thank you just needed a sanity check haha
What's the current status of the Kubernetes training.hacktricks.xyz? Did I have a fever-dream or miss something about that, I believe to have read, there would soon be a Kubernetes training available.
ah that was the message I remember 😅 So I guess it'll be ready, when it's ready, right? 🙂
Some ISPs have blocked the site, use a VPN and see if you have any issues
it'll be ready when it's ready is a good way to define it hahaha hopefully it'll be ready by summer
Is there any role for CRTE?
You have it already
Nickname color is role? red is CRTE?
Yes, if you click on your own name you can see the crte-certified label
Okay!! I checked !! Thank you!!
hey guys
does anyone help me to build a logger software
literally i m facing so many issues
@everyone
Do you want to improve your Cloud, CI/CD & Kubernetes security knowledge?
We are delivering some trainings soon!
🇬🇧 Check the 2 days online training about Cloud, K8s & CI/CD: https://lnkd.in/eib9K72y
🇪🇸 Check our on-site trainings in Spanish at RootedCON:
@modest elbow what about k8s ceet from hacktricks ? 😁
We are on it. In those training you will find a small preview hahaha
Excited for it! The only training for k8 certs that I have seen was from kodecloud. Obviously the focus for those is administration.
which cloud?
I'm currently studying azure red team expert. The part on apps registration, service principals, managed identities had my head spinning, lol
the top 3, check the links for further info
@modest elbow <@&1128840997581889586> hi there, i am currently doing azure apprantice course and 30 days lab access is expiring on 8 feb. I am half-way through labs. I will be busy from mid-feb till end of march. So, i want to continue Azure apprantice course in April.
In April, then i plan to buy 15 days lab extension & continue the course.
Will it be ok, if i only buy extension in April & continue my apprantice labs ?
@wicked cradle Hi! Yes you won't have any issue at all!
I have issue understanding tokens in the azure course, It says that refresh tokens are bound to an audience but later when I read the microsft documentation I have " Refresh tokens are bound to a combination of user and client, but aren't tied to a resource or tenant." so I'm genuily confused (I'm not experienced in Azure, it feels really hard)
you will understand it a bit more when the course talk about FOCI tokens.
But in general refresh tokens should be dound to the audience, but Microsoft is Microsoft so they do some unsecure stuff
I'm genuily confused, (I reached the part on FOCI), in the intro module, I thought that we authenticated with az cli, entraID was providing a refresh token, which later could be used to get access token for other APIS (like storage, arm), I feel dumb, I don't really understand Azure
Ooooo
Tokens in Azure are very confusing no worries. My recommendation for you to understand them would be to play with them.
For example in https://cloud.hacktricks.wiki/en/pentesting-cloud/azure-security/az-basic-information/az-tokens-and-public-applications.html#foci-tokens-privilege-escalation you have a guided tutorial on how to login to get refresh token belonging to a FOCI application that allows to generate other tokens for other APP IDs.
Interestingly this tutorial used to use the App ID of the Azure CLI, but just some weeks ago Microsoft removed that App ID from the FOCI apps. So you can follow the tutorial and see how with a FOCI app you can generate tokens for other apps and the repeat it with the app id "04b07795-8ddb-461a-bbee-02f9e1bf7b46" and se hoe the last step doesn't work (It doesn't allow to generate tokens for other client IDs).
Moreover, the refresh tokens are also generated for other "aud"s, however, as you mentioned, the refresh tokens are not bounded to them. Which unfortunately doesn't mean that any refresh token can generate tokens for any "aud"s. Depending on the "app ID" the token will be able to generate tokens fro different "aud"s. And the same happens with scopes (permissions) also!
"Hidden" in the AzureAppsSweep, you can find https://github.com/carlospolop/AzureAppsSweep/tree/main/GraphAppScopes which is the brute-force I did some months ago to find all the possible combinations based on all the APP IDs I found.
Hi, I'm currently taking the AWS Red Team Expert exam, but I suddenly can't log in to https://training.hacktricks.xyz/signin. I'm getting a "Sign in failed with unknown error". Could you please help me with this?
Yep I'm in the same boat, I was just about to submit a flag too ☠️
You managed to end the exam right?!
Should be fine some time ago
Doing some maintenance now sorry for the inconvenience
Please let us know here when the maintenance is finished
Should be finished now!
Still can't login
Using the new website it works https://hacktricks-training.com/
Learn Cloud Hacking & Become HackTricks Training Certified
Working on another fix now so the old website also works
Both sites are back and looking healthy
Hey guys anyone having trouble with the lab deployment on section 2.8 Azure App Services?
I tried deploying the labs multiple times and I get an error "Error provisioning lesson labs".
Do i have email the hacktricks team?
Create a ticket. If you don’t see the the channel associated with the course check your profile settings
Hey dude thanks, I am getting an error while trying to update the discord hundle ^^ it needs the name#number right?
No, only name, yours is "titfort4t"
Hey DM me if you still have the issue!
Thanks i have managed to add it and the group appeared thanks a lot
I will try to re-deploy and DM you if i still have the issue
https://www.modernsecurity.io/courses/ai-security-certification - may someone done this course? any experience? is this worth it?