Lab - Abusing Identity Providers in AWS

Exploit a misconfigured GitLab Identity Provider in AWS to gain access and compromise the account

This is a lab I created for the cloud security training platform PwnedLabs.io. It offers hands-on experience in navigating and exploiting real-world cloud vulnerabilities. You'll begin with ReadOnly access to an AWS account, uncover a misconfigured GitLab Identity Provider Trust Policy, exploit it, and ultimately compromise the account.

Link to Lab
Blog Post

Last updated

Was this helpful?