From SSRF to Cloud Account Takeover: Attacking the Metadata Service

One SSRF bug in a URL fetcher can reach the cloud metadata endpoint, steal IAM role credentials, and end in full account takeover. Here is the chain, and how to break it.
Read more
Cloud Penetration Testing: Our Methodology for AWS, Azure, and GCP

A working walkthrough of the cloud penetration testing methodology we run against AWS, Azure, and GCP: how we abuse IAM, hunt misconfigurations and exposed storage, pivot from SSRF to instance metadata, escalate privilege, and check whether anyone was watching.
Read more









