multi-stage-attack

1 article
sort: new top best
clear filter
0 8/10

A detailed writeup of a multi-stage attack chain exploiting WAF bypass via DNS enumeration to discover origin server IP, leveraging LFI to bypass Cloudflare, then escalating to SSRF by bypassing Nginx web cache (using query string manipulation), and finally extracting AWS credentials from instance metadata. The attacker discovered that Nginx cache rules didn't account for query parameters, allowing cache bypass via appending '?' to metadata API calls.

Avinash Jain logicbomb Cloudflare AWS Nginx CVE-2019-XXXX (instance metadata exploitation)
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 20 hours ago · details