41554 blogs · [ { "id": "01a0877a-0e12-70a6-9126-ee6cfe51f6f1", "title": "How Hotel Wi-Fi Broke My Tailscale Peer Relay", "url": "https://frichetten.com/blog/how-hotel-wi-fi-broke-my-tailscale-peer-relay/", "published_at": "2026-07-10T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6cfe60dcd5", "title": "Amplified exposure: How AWS flaws made Amplify IAM roles vulnerable to takeover", "url": "https://frichetten.com/blog/amplify-vuln-2024/", "published_at": "2024-04-22T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6cff4e4ac8", "title": "Two Minor Cross-Tenant Vulnerabilities in AWS App Runner", "url": "https://frichetten.com/blog/minor-cross-tenant-vulns-app-runner/", "published_at": "2023-04-03T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6cffc36f31", "title": "Using an Undocumented Amplify API to Leak AWS Account IDs", "url": "https://frichetten.com/blog/undocumented-amplify-api-leak-account-id/", "published_at": "2023-03-27T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d008b2bb9", "title": "A Look at AWS API Protocols", "url": "https://frichetten.com/blog/aws-api-protocols/", "published_at": "2023-01-23T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d00bfe154", "title": "A Confused Deputy Vulnerability in AWS AppSync", "url": "https://frichetten.com/blog/appsync-vulnerability-disclosure/", "published_at": "2022-11-21T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d01614663", "title": "OpenSSL Punycode Vulnerabiliy (CVE-2022-3602)", "url": "https://frichetten.com/blog/openssl-punycode-vuln/", "published_at": "2022-11-01T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d01caad48", "title": "Revisiting Lambda Persistence", "url": "https://frichetten.com/blog/revisiting_lambda_persistence/", "published_at": "2021-09-16T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d02438212", "title": "XSS in the AWS Console", "url": "https://frichetten.com/blog/xss_in_aws_console/", "published_at": "2021-06-03T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d02890e97", "title": "Intercept SSM Agent Communications", "url": "https://frichetten.com/blog/ssm-agent-tomfoolery/", "published_at": "2021-01-27T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d0312cde8", "title": "Enumerate AWS API Permissions Without Logging to CloudTrail", "url": "https://frichetten.com/blog/aws-api-enum-vuln/", "published_at": "2020-10-17T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d0316d29f", "title": "Abusing AWS Connection Tracking", "url": "https://frichetten.com/blog/abusing-aws-connection-tracking/", "published_at": "2020-08-11T06:00:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d03a88ff4", "title": "Abusing GitLab Runners", "url": "https://frichetten.com/blog/abusing-gitlab-runners/", "published_at": "2020-07-11T06:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d042642ec", "title": "CVE-2020-11108: How I Stumbled into a Pi-hole RCE+LPE", "url": "https://frichetten.com/blog/cve-2020-11108-pihole-rce/", "published_at": "2020-05-10T06:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d05038d15", "title": "Escalating Deserialization Attacks (Python)", "url": "https://frichetten.com/blog/escalating-deserialization-attacks-python/", "published_at": "2020-02-23T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d053ed569", "title": "Intercept Linux CLI Tool Traffic", "url": "https://frichetten.com/blog/intercept-linux-cli-tool-traffic/", "published_at": "2020-01-11T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d05bb12f8", "title": "Bypass GuardDuty PenTest Alerts", "url": "https://frichetten.com/blog/bypass-guardduty-pentest-alerts/", "published_at": "2019-09-04T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d06874126", "title": "Hijacking IAM Roles and Avoiding Detection", "url": "https://frichetten.com/blog/hijack-iam-roles-and-avoid-detection/", "published_at": "2019-07-01T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d0712ed3f", "title": "IDOR Attacks", "url": "https://frichetten.com/blog/idor-attacks/", "published_at": "2019-06-04T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d07c589fa", "title": "Security Headers: Content Security Policy", "url": "https://frichetten.com/blog/content-security-policy/", "published_at": "2018-12-03T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d08bcba39", "title": "Angular Universal: Some Insights", "url": "https://frichetten.com/blog/angular-universal/", "published_at": "2018-10-04T23:16:40+00:00" }, { "id": "01a0877a-0e12-70a6-9126-ee6d097dea40", "title": "OSCP Review", "url": "https://frichetten.com/blog/oscp-review/", "published_at": "2018-07-23T23:16:40+00:00" } ] posts Claim your blog
Back to frichetten.com
Blog · corpus.blog/blogs/frichetten.com/posts

frichetten.com

frichetten.com

2026

2024

2023

2022

2021

2020

2019

2018