active Retires on: October 15, 2026
Hard
HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape
A comprehensive penetration testing guide exploiting an SSRF bypass via octal/decimal IP encoding to steal EC2 IMDS credentials, abusing a LocalStack AWS emulator with proxy-only IAM enforcement, injecting malicious YAML into an SQS queue for worker RCE, and escalating through a privileged CodeBuild container with a BASH_FUNC gosu bypass to achieve host root via modprobe usermode-helper abuse.
Table of Contents
Unlock this write-up to reveal its sections.
Content Locked
Have the password? Enter it above to read this write-up.
Comments