All articles

Cloud & AWS Security

AWS misconfigurations are the #1 attack vector we find in product security assessments. These deep dives cover IAM, EC2, Lambda, App Runner, and cloud-native attack paths.

14 articles

Cloud Security Ec2

Backdooring AMIs for Fun and Profit

A walkthrough of how a malicious public AMI can embed a reverse shell backdoor that calls home when a victim launches an EC2 instance from it, giving attackers access to the victim's instance role.

6 following · · 11 min
AWS Cloud Security

Exploiting IAM security Misconfigurations — Part 2

Part 2 of the IAM misconfiguration series: exploiting overly permissive CreatePolicyVersion permissions to escalate privileges and gain access to sensitive AWS resources like S3.

Appsecco · · 4 min
AWS Apprunner

Getting shell and data access in AWS App Runner

What happens when an attacker gains remote code execution in an AWS App Runner container — a research walkthrough of pivoting from RCE to stealing secrets from AWS Secrets Manager.

Appsecco · · 6 min
Cloud Security Aws Security

Exploiting IAM security Misconfigurations — Part 1

How attackers exploit AWS IAM misconfigurations — starting with a misconfigured AssumeRole policy — to perform privilege escalation and move laterally through cloud environments.

Appsecco · · 5 min
AWS Lambda Hacking

Hacking AWS Lambda for security, fun and profit

An introduction to AWS Lambda security vulnerabilities — insecure code, over-permissive roles, and serverless-specific attack vectors — explored hands-on using the ServerlessGoat vulnerable app.

Appsecco · · 10 min
Cloud Security Pentesting

Exploiting weak configurations in Amazon Cognito in AWS

How to detect and exploit misconfigured Amazon Cognito identity pools, covering federated identity abuse and techniques found during real web and mobile application assessments.

Appsecco · · 7 min
Cloud Security Application Security

AWS EC2 IMDSv2 versus an esoteric HTTP Method

An investigation into whether the X-HTTP-Method-Override header can be used to bypass IMDSv2 on AWS EC2 instances — and why the answer is definitively no.

Appsecco · · 5 min

Want to know how we test for these issues in your product?

Get a Security Assessment