EC-Council Certified Ethical Hacker (CEH) v12Cloud ComputingMedium
A penetration tester is attempting to exploit a vulnerable web application hosted on a public cloud provider. During reconnaissance, they discover that the application's underlying compute instances are configured with an Instance Metadata Service (IMS) that is accessible without authentication from within the instance. The tester successfully retrieves temporary security credentials by making a request to 'http://169.254.169.254/latest/meta-data/iam/security-credentials/'. What type of attack is being performed?
- ASQL Injection
- BServer-Side Request Forgery (SSRF)
- CCross-Site Scripting (XSS)
- DOS Command Injection
Show answer & explanationAnswer & explanation
Correct answer: B. Server-Side Request Forgery (SSRF)
The attack involves the web application itself making a request to an internal service (the Instance Metadata Service) based on an attacker's input or exploit. This is the definition of Server-Side Request Forgery (SSRF).
Why the other options are wrong
- A. SQL Injection targets database queries, manipulating them to retrieve or modify data.
- C. XSS involves injecting client-side scripts into web pages viewed by other users, not server-side requests.
- D. OS Command Injection involves executing arbitrary operating system commands on the server.
Server-Side Request Forgery (SSRF)
A web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
- Can be used to target internal systems behind firewalls.
- Commonly exploited to access cloud Instance Metadata Services.
- Mitigated by strict input validation and network segmentation.
Memory trick: SSRF is like making the server fetch the mail from inside the house.