Enhanced Legion Credential Harvester Targets SSH Servers and AWS Credentials
Enhanced Legion Credential Harvester Targets SSH Servers and AWS Credentials
29 May 2023
An updated version of the Python-based, cloud-focused hack tool called Legion—which can extract credentials from vulnerable web servers—has surfaced. The updated variant incorporates the Paramiko module to exploit SSH servers. Furthermore, it can now retrieve specific AWS credentials associated with CloudWatch, DynamoDB, and AWS Owl from Laravel web applications.