🐱
HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape
active Retires: October 15, 2026
Hard

HTB Nimbus Complete Writeup - SSRF, IMDS Credential Theft, LocalStack Abuse & modprobe Container Escape

A comprehensive penetration testing guide exploiting an SSRF bypass via octal/decimal IP encoding to steal EC2 IMDS credentials, abusing a LocalStack AWS emulator with proxy-only IAM enforcement, injecting malicious YAML into an SQS queue for worker RCE, and escalating through a privileged CodeBuild container with a BASH_FUNC gosu bypass to achieve host root via modprobe usermode-helper abuse.

🔒 Content Locked

This writeup is password-protected to comply with HTB rules.

📧 Need access? Enter the password.

Comments