Rhino Security Labs

Strategic & Technical Blog

New Pacu Module:
Secret Enumeration in Elastic Beanstalk

Tyler Ramsbey
April 22, 2025

During a recent AWS penetration test, the client was using a service I do not see very often: AWS Elastic Beanstalk (EBN). This is a service that makes it easy to deploy web applications without managing the underlying infrastructure. The…

Fuzzing Left4Dead 2 with CERT’s
Basic Fuzzing Framework

Weaponizing AWS ECS Task Definitions
to Steal Credentials From Running Containers

CloudGoat AWS Scenario Walkthrough: “EC2_SSRF”

Sebastian Mora

CloudGoat is a tool that can help cloud training by providing vulnerable CTF-style AWS environments to help anyone learn about AWS security. This walkthrough will cover the CloudGoat attack simulation “ec2_ssrf”.
This challenge was…