BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//bsideslv24//talk//MZVN8F
BEGIN:VTIMEZONE
TZID:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20230808T000000
TZNAME:PDT
TZOFFSETFROM:-0700
TZOFFSETTO:-0700
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20231105T020000
RDATE:20241103T020000
TZNAME:PST
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20240310T030000
RDATE:20250309T030000
TZNAME:PDT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:One Port to Serve Them All - Google GCP Cloud Shell Abuse - Hubert
  Lin
DTSTART;TZID=America/Los_Angeles:20240807T143000
DTEND;TZID=America/Los_Angeles:20240807T145000
DTSTAMP:20260807T122006Z
UID:pretalx-bsideslv24-MZVN8F@pretalx.com
DESCRIPTION:The Cloud Shell feature from cloud service providers offers a 
 convenient way to access resources within the cloud\, significantly improv
 ing the user experience for both administrators and developers. However\, 
 even though the spawned instance has a short lifespan\, granting excessive
  permissions could still pose security risks to users. This talk reveals a
 n abuse methodology that leverages an unexpected\, public-facing port in G
 CP Cloud Shell discovered during recon. Through manipulation in Linux Netf
 ilter's NAT table\, it serves various internally running services such as 
 HTTP\, SOCKS\, and SSH within the Cloud Shell container to the public. Thi
 s configuration could be exploited by adversaries to bypass the Google aut
 hentication needed in its Web Preview feature to leak data\, to deliver ma
 licious content\, or to pivot attack traffic through the Google network.
LOCATION:Florentine F
URL:https://pretalx.com/bsideslv24/talk/MZVN8F/
END:VEVENT
END:VCALENDAR
