Instance metadata

Every Compute Engine instance (and GKE node, Cloud Run, and Cloud Build worker) can reach the metadata server at metadata.google.internal (169.254.169.254). It serves the attached service account's OAuth token, its granted scopes, project metadata, and SSH keys, with no authentication beyond a required request header. On a foothold it is the first credential source; reached through a web vulnerability it is a server-side request forgery payload.

What folds in here#

The required header#

Every metadata request needs Metadata-Flavor: Google; requests without it are refused, which is what makes a naive SSRF that cannot set headers harder (and what a ?alt=json and recursive read exploit once it can).

bash
curl -s -H 'Metadata-Flavor: Google' \
  'http://metadata.google.internal/computeMetadata/v1/?recursive=true&alt=json'

References#

Cookie Consent

We use cookies to enhance your experience. Learn more