diff --git a/scenarios/glue_privesc/terraform/sg.tf b/scenarios/glue_privesc/terraform/sg.tf index bd1a270e..7d299cdf 100644 --- a/scenarios/glue_privesc/terraform/sg.tf +++ b/scenarios/glue_privesc/terraform/sg.tf @@ -6,7 +6,7 @@ resource "aws_security_group" "cg-rds-glue-security-group" { from_port = 0 to_port = 0 protocol = "-1" - cidr_blocks = ["0.0.0.0/0"] + cidr_blocks = var.cg_whitelist } egress { from_port = 0 @@ -29,13 +29,13 @@ resource "aws_security_group" "cg-ec2-security-group" { from_port = 22 to_port = 22 protocol = "tcp" - cidr_blocks = ["0.0.0.0/0"] + cidr_blocks = var.cg_whitelist } ingress { from_port = 5000 to_port = 5000 protocol = "tcp" - cidr_blocks = ["0.0.0.0/0"] + cidr_blocks = var.cg_whitelist } egress { from_port = 0 @@ -84,4 +84,4 @@ resource "aws_security_group" "cg-rds-security-group" { Stack = var.stack-name Scenario = var.scenario-name } -} \ No newline at end of file +} diff --git a/scenarios/glue_privesc/terraform/variables.tf b/scenarios/glue_privesc/terraform/variables.tf index 57ac3def..0bbbfbaf 100644 --- a/scenarios/glue_privesc/terraform/variables.tf +++ b/scenarios/glue_privesc/terraform/variables.tf @@ -16,7 +16,6 @@ variable "cgid" { variable "cg_whitelist" { description = "User's public IP address(es)" - default = ["0.0.0.0/0"] type = list(string) } @@ -60,4 +59,4 @@ variable "rds_password" { description = "rds_db_passwrod" default = "bob12cgv" type = string -} \ No newline at end of file +}