Taking Over an AWS Account with SSRF! (ec2_ssrf)

  Рет қаралды 1,096

Tyler Ramsbey

Tyler Ramsbey

Жыл бұрын

Join the Hack Smarter community: hacksmarter.org
--- In this video, we work our way through the "ec2_ssrf" scenario on CloudGoat.
Specifically, I cover the following:
- Enumerating Lambda Functions for secrets
- Enumerating EC2 instances for public web server
- Abusing an SSRF vulnerability in a web server to read AWS metadata
- Searching for sensitive information in S3 buckets
- Fully compromising the environment by stealing credentials of the admin user
Enjoy!
--------------
Introduction to CloudGoat - Full Workshop: • Launch Your First Clou...
Rhino Security Labs Discord: / discord
Work Smarter Discord: / discord
Twitch: hacksmarter.live/

Пікірлер: 3
@rogerhuang4205
@rogerhuang4205 3 ай бұрын
I like the part where u fix and troubleshoot live! Good content and learning, keep it up!
@sitandstand5469
@sitandstand5469 Жыл бұрын
Whats the point after get elliot running lambda function? I thought solus as non prevs user will run it
@TylerRamsbey
@TylerRamsbey Жыл бұрын
Actually, Solus had read access to the function, but could not actually execute it. After Elliot can run the function, privilege escalation would be performed from that point on. This scenario doesn't have anything else built into it -- outside of the scenario goal of running the function :)
Hacking Amazon Cognito! (vulnerable_cognito)
52:18
Tyler Ramsbey
Рет қаралды 1,4 М.
Hacking AWS: Learning the CLI!
27:00
Tyler Ramsbey
Рет қаралды 655
터키아이스크림🇹🇷🍦Turkish ice cream #funny #shorts
00:26
Byungari 병아리언니
Рет қаралды 29 МЛН
I CAN’T BELIEVE I LOST 😱
00:46
Topper Guild
Рет қаралды 88 МЛН
ИРИНА КАЙРАТОВНА - АЙДАХАР (БЕКА) [MV]
02:51
ГОСТ ENTERTAINMENT
Рет қаралды 10 МЛН
Server-Side Request Forgery (SSRF) | Complete Guide
47:04
Rana Khalil
Рет қаралды 63 М.
Deploying GPU Enabled Unikernels to the Cloud
8:39
nanovms
Рет қаралды 40
Securing the Cloud with Amazon Inspector!
1:01:14
Tyler Ramsbey
Рет қаралды 337
Airplane - Detailed Walkthrough - (TryHackMe!)
42:13
Tyler Ramsbey
Рет қаралды 857
Bug Bounty | $2000 for SSRF bypass using DNS rebinding
12:47
Leet Cipher
Рет қаралды 35 М.
XXE Injection - Detailed Walkthrough - (TryHackMe!)
1:04:44
Tyler Ramsbey
Рет қаралды 833
SSRF without impact is NOT a vulnerability
4:37
LiveUnderflow
Рет қаралды 5 М.
Main filter..
0:15
CikoYt
Рет қаралды 14 МЛН
После ввода кода - протирайте панель
0:18
Up Your Brains
Рет қаралды 1 МЛН
Secret Wireless charger 😱 #shorts
0:28
Mr DegrEE
Рет қаралды 2,5 МЛН
YOTAPHONE 2 - СПУСТЯ 10 ЛЕТ
15:13
ЗЕ МАККЕРС
Рет қаралды 163 М.