Skip to content
Home » News

News

Is there an echo in here?

Introduction This is a medium rated CloudFormation challenge. The title is a hint. Look at the CloudFormation template after running setup.sh to solve the challenge. The challenge exploits an “insecure feature” within CloudFormation. You can attempt this challenge here: https://pentesting.cloud/challenge/echo-in-here/

A Token of Gratitude

Introduction IMDSv2 added a lot of addition security to help prevent SSRF attacks and other attacks targeting the meta-data and temporary access keys within. But exactly how secure is it? IMDSv2 Challenge – Bypass the meta-data controls to obtain the… Read More »A Token of Gratitude