SSRF to Cloud Metadata: Stealing IMDS Credentials

Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.

2024-11-19 · 3 min · 561 words · lcz

ProxyLogon (CVE-2021-26855): Dissecting the Exchange SSRF Chain

Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.

2021-03-10 · 3 min · 524 words · lcz