Thomas de Lachaux

Thomas de Lachaux

Thomas is a SecOps Engineer at Padok. He pentests cloud infrastructures to assess their security level to prevent malicious user attacks. He enjoys CTFs and playing piano.

How to pentest AWS Cognito? Attack and remediation explained

How to pentest AWS Cognito? Attack and remediation explained

So, you are pentesting a website, and it uses AWS Cognito. But you don’t know what is this service nor how to abuse it? Let's see how to pwn it!