Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How a startup’s cloud got taken over by a simple form that sends emails

Summary

An SSRF bug in a PHP email form let attackers fetch EC2 IMDSv1 credentials and pivot to S3 buckets and CloudFormation templates with API keys; the walkthrough covers the chain and IMDSv2 mitigation.
Published
Collected

original ↗

Related coverage

back