Media Summary: Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with Starting with no access to the AWS account, we compromise a webapp hosted in an We start off as a fairly high-privileged user who can perform multiple IAM and

Hacking In The Cloud Cloudgoat Ec2 Ssrf - Detailed Analysis & Overview

Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with Starting with no access to the AWS account, we compromise a webapp hosted in an We start off as a fairly high-privileged user who can perform multiple IAM and The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users. We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ... I am posting this raw footage because I am stuck. I'm attempting the

Starting as the low-privilege IAM user Solus, we enumerate the environment, loot secrets from Lambda, exploit Resources: Enroll in my Courses (search for Tyler Ramsbey) Support me on Ko-Fi ...

Photo Gallery

Hacking in the Cloud - Cloudgoat: ec2_ssrf
Hacking in the Cloud - Cloudgoat: ecs_takeover
Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment
Hacking in the Cloud - Cloudgoat: rce_web_app
Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback
Hacking in the Cloud - Cloudgoat: lambda_privesc
Hacking in the Cloud - Cloudgoat: vulnerable_lambda
Hacking in the Cloud - Cloudgoat: cloud_breach_s3
Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)
Stuck on CloudGoat: Need Help with EC2 SSRF Lab
From Zero to Full Admin: How I Hacked AWS Using Lambda & SSRF (CloudGoat Scenario Walkthrough
Taking Over an AWS Account with SSRF! (ec2_ssrf)
View Detailed Profile
Hacking in the Cloud - Cloudgoat: ec2_ssrf

Hacking in the Cloud - Cloudgoat: ec2_ssrf

Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with

Hacking in the Cloud - Cloudgoat: ecs_takeover

Hacking in the Cloud - Cloudgoat: ecs_takeover

Starting with no access to the AWS account, we compromise a webapp hosted in an

Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment

Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment

We start off as a fairly high-privileged user who can perform multiple IAM and

Hacking in the Cloud - Cloudgoat: rce_web_app

Hacking in the Cloud - Cloudgoat: rce_web_app

The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users.

Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback

Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback

This is the second scenario in the

Hacking in the Cloud - Cloudgoat: lambda_privesc

Hacking in the Cloud - Cloudgoat: lambda_privesc

We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ...

Hacking in the Cloud - Cloudgoat: vulnerable_lambda

Hacking in the Cloud - Cloudgoat: vulnerable_lambda

This is the first scenario in the

Hacking in the Cloud - Cloudgoat: cloud_breach_s3

Hacking in the Cloud - Cloudgoat: cloud_breach_s3

This scenario is based off of a real

Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)

Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)

Hacking

Stuck on CloudGoat: Need Help with EC2 SSRF Lab

Stuck on CloudGoat: Need Help with EC2 SSRF Lab

I am posting this raw footage because I am stuck. I'm attempting the

From Zero to Full Admin: How I Hacked AWS Using Lambda & SSRF (CloudGoat Scenario Walkthrough

From Zero to Full Admin: How I Hacked AWS Using Lambda & SSRF (CloudGoat Scenario Walkthrough

Starting as the low-privilege IAM user Solus, we enumerate the environment, loot secrets from Lambda, exploit

Taking Over an AWS Account with SSRF! (ec2_ssrf)

Taking Over an AWS Account with SSRF! (ec2_ssrf)

Resources: Enroll in my Courses (search for Tyler Ramsbey) https://academy.simplycyber.io Support me on Ko-Fi ...

SSRF to Cloud Takeover | Stealing IAM Role Credentials LIVE

SSRF to Cloud Takeover | Stealing IAM Role Credentials LIVE

What if a single

How I Hacked into an AWS ECS Container Using SSRF (Flaws2.cloud Level 3 – Full Walkthrough)

How I Hacked into an AWS ECS Container Using SSRF (Flaws2.cloud Level 3 – Full Walkthrough)

Try the challenge yourself: http://flaws2.

CloudGoat Walkthrough: AWS S3 Breach & EC2 Metadata Exploit

CloudGoat Walkthrough: AWS S3 Breach & EC2 Metadata Exploit

In this

CloudGoat Attack Path: EC2 Access, S3 Secrets, and RDS Takeover (rds_snapshot)

CloudGoat Attack Path: EC2 Access, S3 Secrets, and RDS Takeover (rds_snapshot)

In this

Abusing XXE to SSRF via IMDSv1 & Stealing IAM Role Credentials | AWS EC2 Attack Tutorial

Abusing XXE to SSRF via IMDSv1 & Stealing IAM Role Credentials | AWS EC2 Attack Tutorial

In this hands-on AWS

Hacking AWS || SNS_Secrets - Official Walkthrough (CloudGoat!)

Hacking AWS || SNS_Secrets - Official Walkthrough (CloudGoat!)

Resources: Enroll in my Courses (search for Tyler Ramsbey) https://academy.simplycyber.io Support me on Ko-Fi ...

Creating a FREE AWS Pentesting Lab with CloudGoat!

Creating a FREE AWS Pentesting Lab with CloudGoat!

Resources: Enroll in my Courses (search for Tyler Ramsbey) https://academy.simplycyber.io Support me on Ko-Fi ...