Step 1) Check the availability of these cars




{"Code":"Success","LastUpdated":"2022-05-14T20:30:36Z","Type":"AWS-HMAC","AccessKeyId":"DEMO_ACCESS_KEY_ID","SecretAccessKey":"DEMO_ACESSS_KEY","Token":"DEMO_TOKEN","Expiration":"2022-05-15T03:06:24Z"}

Step 2) Find the vulnerability


Step 3) Run the attacker links


Attack 1: check localhost (it should fail)

Attack 2: check if this is a AWS environment (this should work) (explanation)

Attack 3: check if a role is attached to this AWS entity (this should work)

Attack 4: steal AWS credentials for this role (this should work)