Rhino Security Labs

Technical Blog

CloudGoat Official Walkthrough Series: ‘glue_privesc’

John De Armas
September 10, 2024

CloudGoat is Rhino Security Labs’s tool for deploying “vulnerable by design” AWS infrastructure. This blog post will walk through one of the newest CloudGoat scenarios, glue_privesc. where you will attempt to move through an AWS…

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

CVE-2024-2389:
Command Injection Vulnerability
In Progress Flowmon

CVE-2024-2448:
Authenticated Command Injection
In Progress Kemp LoadMaster

David Yesland

This blog covers 2 vulnerabilities discovered in LoadMaster load balancers. CVE-2024-2448 is an authenticated command injection vulnerability and CVE-2024-2449 is a Cross-Site Request Forgery (CSRF) protection bypass vulnerability. The CSRF…