CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

During a cloud assessment, a tester discovers an SSRF vulnerability in an application hosted on an AWS EC2 instance. The tester uses the vulnerable parameter to send a request to http://169.254.169.254/latest/meta-data/iam/security-credentials/WebAppRole and receives temporary AWS access keys in the response. What does this scenario demonstrate?

  1. AExploitation of the IMDS metadata service via SSRF to steal IAM credentials
  2. BAn S3 bucket misconfiguration exposing public objects
  3. CA Golden Ticket attack against the cloud identity provider
  4. DAn IAM PassRole privilege escalation via EC2 launch permissions
Show answer & explanation

Correct answer: A. Exploitation of the IMDS metadata service via SSRF to steal IAM credentials

The 169.254.169.254 link-local address is the AWS Instance Metadata Service (IMDS); an SSRF vulnerability that reaches this endpoint can retrieve temporary IAM role credentials attached to the instance, a well-known cloud attack chain (especially against IMDSv1). This is distinct from S3 misconfigurations, PassRole abuse, or Kerberos-based Golden Ticket attacks.

Why the other options are wrong

  • B. S3 bucket misconfiguration involves publicly accessible storage objects, not metadata endpoint requests.
  • C. Golden Ticket attacks are an on-premises Active Directory Kerberos technique, unrelated to AWS IMDS.
  • D. PassRole escalation involves attaching a role to a new resource, not stealing credentials via SSRF.

Cloud Metadata Service (IMDS) Exploitation

An attack where SSRF or local access is used to query the cloud instance metadata service (e.g., AWS 169.254.169.254) to steal temporary IAM credentials attached to the instance role.

  • AWS IMDS listens on the link-local address 169.254.169.254
  • IMDSv1 accepts simple GET requests, making it SSRF-vulnerable; IMDSv2 requires token-based session headers
  • Retrieved credentials can be reused to access other AWS resources the role permits

Memory trick: 169.254.169.254 is the cloud's secret credential drawer

More Attacks and Exploits questions