Web Hack List

Collected research

Exploiting SSRF in AWS Elastic Beanstalk

An SSRF in an app hosted on AWS Elastic Beanstalk reaches the instance metadata service and steals the default aws-elasticbeanstalk-ec2-role credentials. The default policy permits listing and writing any elasticbeanstalk-* bucket, so the attacker takes the source and drops a webshell in the deployment bucket, which executes once CodePipeline redeploys or the environment is rebuilt or cloned.

Record

Researcher
Sunil Yadav
Published by
NotSoSecure
Date
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Sunil Yadav, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .