active Retires: October 15, 2026
Hard
HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape
A comprehensive penetration testing guide exploiting an SSRF bypass via octal/decimal IP encoding to steal EC2 IMDS credentials, abusing a LocalStack AWS emulator with proxy-only IAM enforcement, injecting malicious YAML into an SQS queue for worker RCE, and escalating through a privileged CodeBuild container with a BASH_FUNC gosu bypass to achieve host root via modprobe usermode-helper abuse.
Comments