Skip to content

Security Café

Security Research and Services

  • Things we do on a daily basis
    • Red Team (DORA/TIBER) exercises
    • Web Application Penetration Testing
    • Mobile Application Penetration Testing
    • Infrastructure Penetration Testing
    • Vulnerability Assessment
  • CVEs, Talks and Tools
  • Contact
  • About

Tag: post exploitation

7 lesser-known AWS SSM Document techniques for code execution

April 19, 2023 Eduard Agavriloae

A deep dive into AWS SSM Run Command shows that there are multiple documents attackers can use for executing code remotely on EC2 instances. In

Continue reading

EC2StepShell: A Tool for Getting Reverse Shells on Instances with Network Restrictions

March 8, 2023 Eduard Agavriloae

A tool for getting reverse shells in EC2 instances where network communication to your host is restricted. In my last article, AWS ssm:SendCommand or network

Continue reading

AWS ssm:SendCommand or network agnostic built-in RCE as root

January 17, 2023 Eduard Agavriloae

Post-exploitation in cloud can be fun and easy if you have the right permissions. There is no other permission that I would rather have than

Continue reading

Pivoting to internal network via non-interactive shell

August 6, 2015

During a recent penetration test we have experienced the situation where we’ve gained remote code execution with limited privileges to a web server and had

Continue reading

Top Posts

  • Pivoting to internal network via non-interactive shell
  • Introduction to Windows shellcode development – Part 3
  • My experience with the OSCP certification
  • When AI Understands Code: Prompt Injection to RCE
  • Practical JSONP Injection

Blog Stats

  • 671,368 hits

Follow us via Email

Enter your email address to follow this blog and receive notifications of new posts by email.

Join 157 other subscribers

Categories

  • Active Directory (4)
  • Announcements (2)
  • C2 (1)
  • Cloud Security (12)
    • aws (9)
    • Azure (3)
    • Kubernetes (1)
  • Conferences (4)
  • Embedded systems security (3)
    • IoT Pentesting (2)
  • Ethical Hacking (18)
  • General security (14)
  • IT Security Assurance (1)
  • IT Security Audit (3)
  • Metasploit (1)
  • Misc (21)
    • Artificial Intelligence (2)
    • Code Review (1)
    • CVE (1)
  • Mobile security (13)
  • Network security (7)
  • Operating systems (2)
  • Penetration Testing (25)
  • Pentest techniques (30)
  • Research (3)
  • Web security (13)
  • Wireless security (1)
Powered by WordPress.com.

Loading Comments...