CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A web application hosted on an AWS EC2 instance accepts a URL parameter used to fetch and display remote images. A tester modifies the parameter to point to an internal address and successfully retrieves temporary IAM credentials. Which attack was performed?
- AServer-Side Request Forgery (SSRF)
- BInsecure Direct Object Reference (IDOR)
- CCross-Site Request Forgery (CSRF)
- DXML External Entity (XXE) injection
Show answer & explanationAnswer & explanation
Correct answer: A. Server-Side Request Forgery (SSRF)
SSRF occurs when an attacker manipulates a server-side request to reach unintended internal resources, such as the cloud metadata service at 169.254.169.254, exposing IAM credentials. XXE relates to XML parsing, CSRF forces a victim's browser to make unwanted requests, and IDOR involves accessing unauthorized objects via direct references.
Why the other options are wrong
- B. IDOR involves referencing unauthorized object IDs, unrelated to server-initiated requests.
- C. CSRF targets the victim's browser session, not server-side fetches.
- D. XXE exploits XML parsers, not URL-fetching parameters.
Server-Side Request Forgery (SSRF)
A vulnerability where an attacker tricks a server into making requests to unintended locations, often internal services or cloud metadata endpoints.
- Common target: 169.254.169.254 cloud metadata service
- Can lead to credential theft and internal network scanning
- Mitigated by allow-listing and disabling metadata access without IMDSv2
Memory trick: 'Server Sends Requests For you' — abuse the server as a proxy to reach 169.254.169.254