Rhino Security Labs

Strategic Blog

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

John De Armas
December 3, 2024

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…

CloudGoat: New Scenario and Walkthrough (sns_secrets)

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

CVE-2024-1212:
Unauthenticated Command Injection
In Progress Kemp LoadMaster

David Yesland

While researching the Progress Kemp LoadMaster load balancer we discovered an unauthenticated command injection in the administrator web interface of the appliance. This allowed full compromise of the LoadMaster if you could reach the…