Beginner Friendly red team icon   azure

Escalate from SSJI to EKS

Server-side JavaScript injection gives an attacker code execution where defenders least expect it. Escalate from SSJI through IAM and IDOR weaknesses to reach an Amazon EKS cluster.

Overview

Server-side JavaScript injection gives an attacker code execution where defenders least expect it. In this lab you will escalate from SSJI through IAM and IDOR weaknesses to reach an Amazon EKS cluster.

Scenario

You are on a red team engagement against Mega Big Tech. A Node.js web application is in scope. Show how server-side injection can be chained into access to the Kubernetes cluster behind it.

Lab prerequisites
  • Familiarity with the Linux command line
  • Familiarity with AWS and web application attacks
Learning outcomes
  • Exploit server-side JavaScript injection (SSJI)
  • Abuse insecure direct object references (IDOR)
  • Enumerate data in DynamoDB
  • Abuse AWS IAM to expand access
  • Pivot into an Amazon EKS cluster
Real-world context

Injection flaws in server-side JavaScript are frequently missed by traditional testing. In cloud environments they can be the first link in a chain that ends at the container orchestration layer.

platform mock(1)

Cloud Security Training To Protect Your Business

Pwned Labs for Business gives your team access to dedicated business content, including labs and cyber ranges.

We also offer in-person or remote workshops, and our cloud penetration services are helping businesses become more secure!