Rhino Security Labs

Technical Blog

CloudGoat Official Walkthrough Series: ‘sqs_flag_shop’

John De Armas
December 3, 2024

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, sqs_flag_shop. where you will attempt to move through an AWS…

CloudGoat: New Scenario and Walkthrough (sns_secrets)

CloudGoat Official Walkthrough Series: ‘glue_privesc’

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

Tyler Ramsbey

During research on the Vestaboard web platform, the Rhino research team identified three instances of Broken Access Controls.

Read-Access to other Vestaboards. 
Ability to update names of other users. 
Privilege escalation from Admin to…