Rhino Security Labs

Strategic & Technical Blog

CloudGoat: New Scenario and Walkthrough (sns_secrets)

Tyler Ramsbey
October 15, 2024

This is a full walkthrough for the new sns_secrets scenario on CloudGoat. 
CloudGoat allows people to hone their cloud security skills by completing several “capture-the-flag” challenges. Full set-up instructions are on the CloudGoat…

Vestaboard: Exploring Broken Access Controls and Privilege Escalation

CVE-2024-2389:
Command Injection Vulnerability
In Progress Flowmon

CVE-2024-2448:
Authenticated Command Injection
In Progress Kemp LoadMaster

David Yesland

This blog covers 2 vulnerabilities discovered in LoadMaster load balancers. CVE-2024-2448 is an authenticated command injection vulnerability and CVE-2024-2449 is a Cross-Site Request Forgery (CSRF) protection bypass vulnerability. The CSRF…