CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A web application hosted on an AWS EC2 instance accepts a URL parameter used to fetch and display remote images. A tester modifies the parameter to point to an internal address and successfully retrieves temporary IAM credentials. Which attack was performed?

  1. AServer-Side Request Forgery (SSRF)
  2. BInsecure Direct Object Reference (IDOR)
  3. CCross-Site Request Forgery (CSRF)
  4. DXML External Entity (XXE) injection
Show answer & explanation

Correct answer: A. Server-Side Request Forgery (SSRF)

SSRF occurs when an attacker manipulates a server-side request to reach unintended internal resources, such as the cloud metadata service at 169.254.169.254, exposing IAM credentials. XXE relates to XML parsing, CSRF forces a victim's browser to make unwanted requests, and IDOR involves accessing unauthorized objects via direct references.

Why the other options are wrong

  • B. IDOR involves referencing unauthorized object IDs, unrelated to server-initiated requests.
  • C. CSRF targets the victim's browser session, not server-side fetches.
  • D. XXE exploits XML parsers, not URL-fetching parameters.

Server-Side Request Forgery (SSRF)

A vulnerability where an attacker tricks a server into making requests to unintended locations, often internal services or cloud metadata endpoints.

  • Common target: 169.254.169.254 cloud metadata service
  • Can lead to credential theft and internal network scanning
  • Mitigated by allow-listing and disabling metadata access without IMDSv2

Memory trick: 'Server Sends Requests For you' — abuse the server as a proxy to reach 169.254.169.254

More Attacks and Exploits questions