>_
From Web RCE to GCP Project Takeover via the Metadata Service
A full attack chain against a lab target: leaking a .git directory, finding an unsanitized system() call, then abusing the GCP instance metadata service to mint an OAuth token for a cloud-platform-scoped service account and exfiltrate a protected object from Cloud Storage.
2024-03-18