# rhinosecuritylabs.com > AI-optimized mirror of rhinosecuritylabs.com containing 25 pages totalling 17,545 words of clean markdown content, structured data, and semantic HTML. Original source: https://rhinosecuritylabs.com/. Last updated: 2026-06-16T02:42:15.295Z. Each page is available as HTML (with JSON-LD structured data) and Markdown (text-only, ideal for LLMs and RAG). ## Homepage - [Deep-Dive Penetration Testing Services](/content/site-root.html): Rhino Security Labs is a top penetration testing company specializing in cloud (AWS, GCP, Azure), network pentesting, and webapp pentesting in Seattle. (690 words) ## Articles & Blog Posts - [disclosures/index.html](/content/disclosures/index.html) (1 words) - [research/cve-2024-55963-unauthenticated-rce-in-appsmith/index.html](/content/research/cve-2024-55963-unauthenticated-rce-in-appsmith/index.html) (1 words) - [Cloud Breach: Compromising AWS IAM Credentials](/content/aws/aws-iam-credentials-get-compromised/index.html) (2,119 words) - [Multiple CVEs in Infoblox NetMRI: RCE, Auth Bypass, SQLi, and File Read Vulnerabilities](/content/research/infoblox-multiple-cves/index.html): While performing research on Infoblox's NetMRI network automation and configuration management solution, we discovered 5 vulnerabilities. (1,413 words) - [Exploring the Power of Phished Persistent Cookies in AWS](/content/aws/aws-phished-persistent-cookies/index.html): Phished cookies in AWS still work even after the user changes their password. In this post, we explore the limitations of the persistent cookies in AWS. (1,350 words) - [AWS IAM Privilege Escalation – Methods and Mitigation](/content/aws/aws-privilege-escalation-methods-mitigation/index.html): At Rhino Security Labs, our focus is AWS penetration testing and AWS security research. This AWS IAM shows privilege escalation in AWS and other clouds. (4,873 words) - [IBM AIX Bellmail Privilege Escalation Vulnerability \[CVE-2016-8972\]](/content/vulnerability-disclosure/ibm-aix-bellmail-vulnerability/index.html) (154 words) - [Vulnerability Disclosures](/content/disclosure-sitemap-xml.html) (32 words) - [Assume the Worst: Enumerating AWS Roles through ‘AssumeRole’](/content/aws/assume-worst-aws-assume-role-enumeration/index.html) (1,474 words) - [CloudGoat goes Serverless: A walkthrough of Vulnerable Lambda Functions](/content/cloud-security/cloudgoat-vulnerable-lambda-functions/index.html): This post walks through exploiting serverless environments and AWS Lambda functions via the CloudGoat vulnerable_lambda scenario. (1,167 words) - [Four Things Every Penetration Test Report Should Have](/content/penetration-testing/four-things-every-penetration-test-report/index.html): There are 4 things you should look for in pentest documentation. These key aspects of reporting are critical to reducing risk and fixing vulnerabilities. (900 words) - [Antivirus Security Analysis P1: Technical Introduction](/content/enterprise-security/antivirus-security-analysis-p1-technical-introduction.html): Antivirus is our last line of defense from threats online, but is antivirus losing ground? Part 1: Antivirus security analysis and technical detail. (1,156 words) - [Unitrends Enterprise Backup Local File Inclusion](/content/vulnerability-disclosure/unitrends-enterprise-backup-local-file-inclusion/index.html) (189 words) - [Unitrends Enterprise Backup Remote Code Execution in reports.php File](/content/vulnerability-disclosure/unitrends-enterprise-backup-remote-code-execution-in-reports-php-file.html) (190 words) - [Unitrends Enterprise Backup Privilege Escalation in users.php File \[CVE-2017-7284\]](/content/vulnerability-disclosure/unitrends-enterprise-backup-privilege-escalation-in-users-php-file.html) (176 words) - [Vishing Assessment Services](/content/assessment-services/social-engineering/vishing-assessments/index.html): Experts in vishing (voice phishing) social engineering testing. Experts in phone call vishing, smshing, and other similar techniques. (601 words) - [Jenkins Information Disclosure to Unauthenticated Users](/content/vulnerability-disclosure/jenkins-information-disclosure-to-unauthenticated-users.html): An authorization vuln in Jenkins Git Plugin ver 3.7.0 and earlier in GitStatus.java allows an attacker with network access to get a list of nodes and users. (104 words) - [Epson Authentication Bruteforce Vulnerability \[CVE-2017-12861\]](/content/vulnerability-disclosure/epson-authentication-bruteforce-vulnerability/index.html) (164 words) - [Epson Hard-Coded Credentials Vulnerability \[CVE-2017-12860\]](/content/vulnerability-disclosure/epson-hard-coded-credentials-vulnerability/index.html) (155 words) - [post-sitemap-xml.html](/content/post-sitemap-xml.html) (428 words) - [Contact Us](/content/contact/index.html): Contact us for more information on penetration testing services | Phone: (888) 944-8679 | Seattle, WA (110 words) - [sitemap_index-xml.html](/content/sitemap_index-xml.html) (8 words) - [page-sitemap-xml.html](/content/page-sitemap-xml.html) (86 words) - [article_type-sitemap-xml.html](/content/article_type-sitemap-xml.html) (4 words) ## Resources - [Full Page Index](/index.html): Browse all cached pages with rich metadata - [About This Cache](/content/about.html): Methodology, technical details, and usage guidelines - [XML Sitemap](/sitemap.xml): Machine-readable sitemap for crawler discovery - [Robots.txt](/robots.txt): Crawler directives