Beginner Friendly
![]()
Escalate from Prototype Pollution to EKS Takeover
A single prototype pollution flaw in a Node.js application can cascade into remote code execution, and from there into a full Amazon EKS cluster takeover. Chain the web bug through container breakout and RBAC abuse to own the cluster.
Overview
Prototype pollution is easy to overlook and dangerous to ignore. In this lab you will exploit a prototype pollution flaw in a Node.js application, gain remote code execution, and escalate all the way to an Amazon EKS cluster takeover.
Scenario
You are on a red team engagement against Mega Big Tech. A customer-facing Node.js application is in scope. Show how a single application flaw can end in full control of the Kubernetes cluster behind it.
Lab prerequisites
- Familiarity with the Linux command line
- Familiarity with AWS and Kubernetes
Learning outcomes
- Exploit prototype pollution in a Node.js and EJS application
- Achieve remote code execution through command injection
- Query the EC2 Instance Metadata Service (IMDS) for credentials
- Enumerate S3 and use AWS Systems Manager (SSM)
- Break out of a container running on containerd
- Abuse overly permissive Kubernetes RBAC
- Access data stored in PostgreSQL
Real-world context
Prototype pollution has led to real-world remote code execution in widely used JavaScript libraries. In cloud-hosted Kubernetes environments, a single application flaw can cascade into cluster-wide compromise.
Cloud Security Training To Protect Your Business
Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.
We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!