Media Summary: Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ... The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users. We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ...

Hacking In The Cloud Cloudgoat Cloud Breach S3 - Detailed Analysis & Overview

Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ... The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users. We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ... Resources: Enroll in my Courses (search for Tyler Ramsbey) Support me on Ko-Fi ... This is the third scenario in AWS. We will attack an AWS environment as an unauthenticated attacker and exfiltrate data using EC2 ... This video was originally sponsored by ITProTV. We've since launched NetworkChuck Academy, our own place to learn IT: ...

Demo for ECE 101 presentation. Source code is located here: Starting as an anonymous outsider with no access or privileges, exploit a misconfigured reverse-proxy server to query the EC2 ... Purchase my Bug Bounty Course here bugbounty.nahamsec.training Buy Me Coffee: ...

Photo Gallery

Hacking in the Cloud - Cloudgoat: cloud_breach_s3
Hacking in the Cloud - Cloudgoat: ecs_takeover
Hacking in the Cloud - Cloudgoat: rce_web_app
Hacking in the Cloud - Cloudgoat: lambda_privesc
Breach in the Clouds (Detailed Walkthrough) -- || Pwned Labs LIVE!
AWS Hacking | Cloud-Goat : Cloud Breach S3 (HEB)
CloudGoat Walkthrough: AWS S3 Breach & EC2 Metadata Exploit
intro to cloud hacking (leaky buckets)
CloudGoat Attack Path: EC2 Access, S3 Secrets, and RDS Takeover (rds_snapshot)
ECE 101: cloudgoat s3 breach
cloud_breach_s3 / AWS cloud hacking - download the confidential files from the AWS S3 bucket.
Cloud Hacking: The Basics
Sponsored
View Detailed Profile
Hacking in the Cloud - Cloudgoat: cloud_breach_s3

Hacking in the Cloud - Cloudgoat: cloud_breach_s3

This scenario is based off of a real

Hacking in the Cloud - Cloudgoat: ecs_takeover

Hacking in the Cloud - Cloudgoat: ecs_takeover

Starting with no access to the AWS account, we compromise a webapp hosted in an EC2 instance by finding both an SSRF and ...

Hacking in the Cloud - Cloudgoat: rce_web_app

Hacking in the Cloud - Cloudgoat: rce_web_app

The objective of this scenario was to gain access to an RDS instance. We were provided with the credentials of two different users.

Hacking in the Cloud - Cloudgoat: lambda_privesc

Hacking in the Cloud - Cloudgoat: lambda_privesc

We start off as a low-privileged user who can perform IAM Get and IAM List on all resources. In addition, this user can assume a ...

Breach in the Clouds (Detailed Walkthrough) -- || Pwned Labs LIVE!

Breach in the Clouds (Detailed Walkthrough) -- || Pwned Labs LIVE!

Resources: Enroll in my Courses (search for Tyler Ramsbey) https://academy.simplycyber.io Support me on Ko-Fi ...

Sponsored
AWS Hacking | Cloud-Goat : Cloud Breach S3 (HEB)

AWS Hacking | Cloud-Goat : Cloud Breach S3 (HEB)

This is the third scenario in AWS. We will attack an AWS environment as an unauthenticated attacker and exfiltrate data using EC2 ...

CloudGoat Walkthrough: AWS S3 Breach & EC2 Metadata Exploit

CloudGoat Walkthrough: AWS S3 Breach & EC2 Metadata Exploit

In this

intro to cloud hacking (leaky buckets)

intro to cloud hacking (leaky buckets)

This video was originally sponsored by ITProTV. We've since launched NetworkChuck Academy, our own place to learn IT: ...

CloudGoat Attack Path: EC2 Access, S3 Secrets, and RDS Takeover (rds_snapshot)

CloudGoat Attack Path: EC2 Access, S3 Secrets, and RDS Takeover (rds_snapshot)

In this

ECE 101: cloudgoat s3 breach

ECE 101: cloudgoat s3 breach

Demo for ECE 101 presentation. Source code is located here: https://github.com/RhinoSecurityLabs/

cloud_breach_s3 / AWS cloud hacking - download the confidential files from the AWS S3 bucket.

cloud_breach_s3 / AWS cloud hacking - download the confidential files from the AWS S3 bucket.

Starting as an anonymous outsider with no access or privileges, exploit a misconfigured reverse-proxy server to query the EC2 ...

Cloud Hacking: The Basics

Cloud Hacking: The Basics

Purchase my Bug Bounty Course here bugbounty.nahamsec.training Buy Me Coffee: ...

Introduction to CloudGoat -- [Learn AWS Pentesting!]

Introduction to CloudGoat -- [Learn AWS Pentesting!]

Resources: Enroll in my Courses (search for Tyler Ramsbey) https://academy.simplycyber.io Support me on Ko-Fi ...