Netskope Threat Labs
GovWare

GovWare - One Port to Serve Them All - GCP Cloud Shell Abuse

Level 1, Tech Talk Area, Sands Expo and Convention Centre, Singapore
GovWare - One Port to Serve Them All - GCP Cloud Shell Abuse
Presented by
About this talk

Join Hubert Lin at GovWare for “One Port to Serve Them All - GCP Cloud Shell Abuse” to learn how an unexpected public port and Linux Netfilter manipulation can expose internal services. Discover how attackers can bypass Google authentication, leak data, or reroute traffic. Get practical insights to protect your cloud environment from these hidden threats.

The Cloud Shell feature from cloud service providers offers a convenient way to access resources within the cloud, significantly improving the user experience for both administrators and developers. However, even though the spawned instance has a short lifespan, granting excessive permissions could still pose security risks to users. This talk reveals an abuse methodology that leverages an unexpected, public-facing port in GCP Cloud Shell discovered during recon. Through manipulation in Linux Netfilter’s NAT table, it serves various internally running services such as HTTP, SOCKS, and SSH within the Cloud Shell container to the public. This configuration could be exploited by adversaries to bypass the Google authentication needed in its Web Preview feature to leak data, to deliver malicious content, or to pivot attack traffic through the Google network.