Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sichere ProgrammierungI Built FeedbackMind AI So Customer Feedback Wouldn’t Be Forgotten(30.09.2026 um 03:50 Uhr)
••
Sichere ProgrammierungWhat actually gets sent to an AI provider when you ask?(30.09.2026 um 03:52 Uhr)
•
Sichere ProgrammierungWhy coding agents should work on a copy of your repo(30.09.2026 um 03:53 Uhr)
••••••
Sichere ProgrammierungGetting started with C# SOLID Principles(30.09.2026 um 04:00 Uhr)
•
Sichere ProgrammierungI Built FeedbackMind AI So Customer Feedback Wouldn’t Be Forgotten(30.09.2026 um 03:50 Uhr)
••
Sichere ProgrammierungWhat actually gets sent to an AI provider when you ask?(30.09.2026 um 03:52 Uhr)
•
Sichere ProgrammierungWhy coding agents should work on a copy of your repo(30.09.2026 um 03:53 Uhr)
••••••
Sichere ProgrammierungGetting started with C# SOLID Principles(30.09.2026 um 04:00 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

25,000$ Bounty — Simple SSRF Led to AWS Credentials Exposure

Timeline 📅 Reported: November 23, 2023 ✅ Fixed: November 24, 2023 💰 Bounty: $25,000 Severity: Critical (9.8/10) Introduction Server Side Request Forgery (SSRF) is one of the most dangerous vulnerabilities in web applications, especially …

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!

Timeline




  • 📅 Reported: November 23, 2023

  • ✅ Fixed: November 24, 2023

  • 💰 Bounty: $25,000

  • Severity: Critical (9.8/10)
    Introduction
    Server Side Request Forgery (SSRF) is one of the most dangerous vulnerabilities in web applications, especially when it allows attackers to access internal services or cloud metadata endpoints.
    Recently, a researcher found a critical SSRF vulnerability in an Analytics Reports feature that exposed AWS credentials, which could potentially allow full control over cloud services.
    In this article, I’ll break down the vulnerability, how it was exploited, and how such attacks can be prevented.
    What is SSRF?
    Server Side Request Forgery (SSRF) happens when an attacker tricks a web server into making requests to internal services or external systems.
    Types of SSRF Attacks:


  • Basic SSRF — The attacker forces a server to make a request to an unintended destination.


  • Blind SSRF — The response is not visible to the attacker, but actions may still be executed on the target system.


  • SSRF to Internal Services — Attackers exploit internal APIs or cloud metadata endpoints, gaining unauthorized access.



Read the Complete Writeup on Medium - https://cyberw1ng.medium.com/25-000-bounty-simple-ssrf-led-to-aws-credentials-exposure-a6938e0875f9

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten 25,000$ Bounty — Simple SSRF Led to AWS Credentials Exposure

Thematisch verwandte Begriffe: 25000, Bounty, Simple, SSRF · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-71189 | An attacker can construct a request that, if issued by another applicati…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag