CompTIA PenTest+ (PT0-003)Attacks and ExploitsEasy
A penetration tester is evaluating a web application that includes a feature for generating PDF reports. The application accepts a URL parameter, `template_url`, which is used to fetch an HTML template from a remote server to render the PDF. The tester provides a value of `http://169.254.169.254/latest/meta-data/` for the `template_url` parameter and observes that the generated PDF contains what appears to be AWS instance metadata. Which type of attack did the tester successfully execute?
- ACross-Site Scripting (XSS)
- BSQL Injection (SQLi)
- CServer-Side Request Forgery (SSRF)
- DXML External Entity (XXE) Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Server-Side Request Forgery (SSRF)
The tester successfully tricked the server into making a request to an internal resource (AWS metadata service) on its behalf, which is the definition of Server-Side Request Forgery. The application's vulnerability allowed it to fetch and process data from an attacker-controlled internal URL.
Why the other options are wrong
- A. XSS involves injecting malicious scripts into content viewed by other users, which is not what occurred here.
- B. SQLi targets databases and involves injecting malicious SQL queries, which is not relevant to fetching URLs for PDF generation.
- D. XXE injection exploits vulnerabilities in XML parsers to access local files or network resources, but the attack vector here was a URL parameter, not an XML input.
Server-Side Request Forgery (SSRF)
A web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing. This can be used to target internal systems behind firewalls or other protected networks.
- Server is tricked into making requests.
- Can target internal network resources.
- Often used to access cloud metadata services.
Memory trick: Server sees, Server fetches, Server spills secrets.