Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

How I gained access to chef, docker, AWS, and MongoDB instances in a single request

Summary

An SSRF in Yahoo's small business platform exposed an internal config.json and led to access to chef, Docker, AWS and MongoDB instances—via a screenshot-endpoint trick for closed networks.
Published
Collected

original ↗

Related coverage

back