GCP
GCP misconfigurations that commonly lead to data exposure and privilege escalation. Each subpage includes description, proof, and remediation.
In this section
- GCS Public BucketsGoogle Cloud Storage (GCS) buckets become public when IAM bindings grant allUsers or allAuthenticatedUsers…
- Service Account Over-Privilege and KeysOver‑privileged service accounts (SAs) and long‑lived user‑managed keys enable broad access across projects and offline abuse if stolen.
- Metadata Server SSRF and Default ScopesServer‑side request forgery (SSRF) to the GCE metadata server (http://metadata.google.internal) can steal…
- Cloud SQL Public ExposureCloud SQL instances with public IPs and permissive authorized networks are reachable from the internet, enabling brute‑force and exploit attempts.
- IAM Misconfig and Lateral MovementGranting roles/iam.serviceAccountUser or roles/iam.serviceAccountTokenCreator on powerful service accounts…
- Cloud Functions/Run UnauthenticatedAllowing unauthenticated invocation (allUsers invoker) exposes Cloud Functions or Cloud Run services publicly,…
- Audit Logging and Retention GapsDisabling Admin or Data Access logs, not exporting logs centrally, or using short retention windows reduces…
- VPC Firewall Open IngressVPC firewall rules allowing 0.0.0.0/0 (or broad ranges) to sensitive ports (SSH/RDP/DB/ICMP) expose workloads…
Last updated