Exploiting Ssrf To Cloud Metadata

Adjudicate whether a server-side request-forgery primitive actually reaches high-value internal targets, especially a cloud instance metadata endpoint that hands out credentials. Covers proving the fetch is attacker-steered, reaching link-local and internal addresses, defeating allowlist and parser-based filters through DNS rebinding and URL confusion, retrieving instance credentials, and blind out-of-band confirmation. Use when a feature fetches a URL, host, or address the user can influence, or when triaging an SSRF lead for real impact.

UnboundCompute 7e323d0 7.0 KB Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/exploiting-ssrf-to-cloud-metadata commit 7e323d008b

Frequently asked questions

npx skillmds@latest add unboundcompute/exploiting-ssrf-to-cloud-metadata