Rhino Security Labs

Strategic Blog

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

John De Armas

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…

CloudGoat: New Scenario and Walkthrough (sns_secrets)

CloudGoat Official Walkthrough Series: ‘glue_privesc’

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

Tyler Ramsbey

During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.

Read-Access to other Vestaboards. 
Ability to update names of other users. 
Privilege escalation from Admin to…