Beginner Friendly red team icon   azure

Abuse SSTI and IAP Tunneling to Increase Access

Server-side template injection opens the door and Identity-Aware Proxy tunneling widens it. Chain SSTI to code execution and tunnel through GCP IAP to reach Cloud SQL and beyond.

Overview

Server-side template injection opens the door and Identity-Aware Proxy tunneling widens it. In this lab you will chain SSTI to code execution and tunnel through GCP IAP to reach Cloud SQL and beyond.

Scenario

You are on a red team engagement against Mega Big Tech, whose applications run on Google Cloud. A public web application is in scope. Show how a template injection flaw can lead to deeper network access.

Lab prerequisites
  • Familiarity with the Linux command line
  • Familiarity with Google Cloud and web application attacks
Learning outcomes
  • Exploit server-side template injection (SSTI) for code execution
  • Tunnel into private resources through GCP Identity-Aware Proxy (IAP)
  • Access a Cloud SQL database
  • Loot Google Cloud Storage
  • Abuse Cloud Run and Cloud Build
Real-world context

Template injection flaws routinely lead to full remote code execution. Identity-Aware Proxy is designed to protect internal services, but misconfiguration can turn it into a tunnel for attackers.

platform mock(1)

Cloud Security Training To Protect Your Business

Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.

We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!