Main Takeaway: Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with EC2 access ... Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ...

Hacking In The Cloud Cloudgoat 27739 -

Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with EC2 access ... Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ... We start off as a fairly high-privileged user who can perform multiple IAM and EC2 API calls.

Important details found

  • Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with EC2 access ...
  • Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ...
  • We start off as a fairly high-privileged user who can perform multiple IAM and EC2 API calls.
  • We start off as a low-privileged user who can perform IAM Get and IAM List on all resources.

Why this topic is useful

This topic is useful when readers need a quick overview first, then want to move into supporting details and related references.

Sponsored

Frequently Asked Questions

Why are related topics included?

Related topics help readers compare nearby references and understand the broader subject.

What is this page about?

This page summarizes Hacking In The Cloud Cloudgoat 27739 and connects it with related entries, references, and supporting context.

Is the information always complete?

Not always. Some topics may need verification from official or primary sources.

Visual References

Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment
Hacking in the Cloud - Cloudgoat: ec2_ssrf
Hacking in the Cloud - Cloudgoat: lambda_privesc
Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback
Hacking in the Cloud - Cloudgoat: ecs_takeover
Hacking in the Cloud - Cloudgoat: rce_web_app
Hacking in the Cloud - Cloudgoat: cloud_breach_s3
Hacking in the Cloud - Cloudgoat: vulnerable_lambda
Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)
How I Hacked the Cloud—A Step-by-Step Roadmap
Sponsored
View Full Details
Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment

Hacking in the Cloud - Cloudgoat: iam_privesc_by_attachment

We start off as a fairly high-privileged user who can perform multiple IAM and EC2 API calls. Using these permissions, it was ...

Hacking in the Cloud - Cloudgoat: ec2_ssrf

Hacking in the Cloud - Cloudgoat: ec2_ssrf

Starting off as a low-privileged user, a misconfiguration in the Lambda service made lateral movement to a user with EC2 access ...

Hacking in the Cloud - Cloudgoat: lambda_privesc

Hacking in the Cloud - Cloudgoat: lambda_privesc

We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ...

Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback

Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback

Read more details and related context about Hacking in the Cloud - Cloudgoat: iam_privesc_by_rollback.

Hacking in the Cloud - Cloudgoat: ecs_takeover

Hacking in the Cloud - Cloudgoat: ecs_takeover

Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ...

Hacking in the Cloud - Cloudgoat: rce_web_app

Hacking in the Cloud - Cloudgoat: rce_web_app

The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users.

Hacking in the Cloud - Cloudgoat: cloud_breach_s3

Hacking in the Cloud - Cloudgoat: cloud_breach_s3

Read more details and related context about Hacking in the Cloud - Cloudgoat: cloud_breach_s3.

Hacking in the Cloud - Cloudgoat: vulnerable_lambda

Hacking in the Cloud - Cloudgoat: vulnerable_lambda

Read more details and related context about Hacking in the Cloud - Cloudgoat: vulnerable_lambda.

Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)

Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios)

Read more details and related context about Hacking Cloud – 1(AWS) A(manual cloudgoat scenarios).

How I Hacked the Cloud—A Step-by-Step Roadmap

How I Hacked the Cloud—A Step-by-Step Roadmap

Read more details and related context about How I Hacked the Cloud—A Step-by-Step Roadmap.