CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…
During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.
Read-Access to other Vestaboards.
Ability to update names of other users.
Privilege escalation from Admin to…