Security · 8h ago
AWS Red Team Lab Shows How to Steal IAM Credentials via IMDSv2
A lab demonstrates exploiting a command injection vulnerability in a web app to achieve RCE on an EC2 instance. The attacker then queries IMDSv2 to obtain a session token and extract IAM role credentials. Those credentials are used to access sensitive data in S3.
Meridian48 take
While IMDSv2 adds a token requirement, this lab shows it's not a silver bullet—RCE still bypasses it, reinforcing the need for defense in depth.
Read the full reporting
Cybr Academy - [LAB] Compromise EC2 IMDSv2 with RCE (AWS Red Teaming) →
DEV Community
aws-securityimdsv2-exploitation