Full ATO (1 Click) via custom metadata manipulation in AWS Cognito Misconfigured Application
How i found critical ATO via new hidden AWS Cognito Misconfiguration
Aug 31, 20256 min read80
Pinned

Search for a command to run...
How i found critical ATO via new hidden AWS Cognito Misconfiguration

How automation tricks can be useful to escalate your findings from 1 to 22

السلام عليكم Assalamualaikum, everyone! Let me introduce myself first ❤️ I’m Hazem El-Sayed (zoma), a Junior Computer Science student and an Offensive Security enthusiast. Currently, I’m hunting for bugs in Vulnerability Disclosure Programs (VDPs), a...
