🐱
HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape
active Retires on: October 15, 2026
Hard

HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape

A comprehensive penetration testing guide exploiting an SSRF bypass via octal/decimal IP encoding to steal EC2 IMDS credentials, abusing a LocalStack AWS emulator with proxy-only IAM enforcement, injecting malicious YAML into an SQS queue for worker RCE, and escalating through a privileged CodeBuild container with a BASH_FUNC gosu bypass to achieve host root via modprobe usermode-helper abuse.

Table of Contents
Unlock this write-up to reveal its sections.

Comments