Collected research
Exploiting SSRF in AWS Elastic Beanstalk
An SSRF in an app hosted on AWS Elastic Beanstalk reaches the instance metadata service and steals the default aws-elasticbeanstalk-ec2-role credentials. The default policy permits listing and writing any elasticbeanstalk-* bucket, so the attacker takes the source and drops a webshell in the deployment bucket, which executes once CodePipeline redeploys or the environment is rebuilt or cloned.
Record
- Researcher
- Sunil Yadav
- Published by
- NotSoSecure
- Date
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Sunil Yadav, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .