Skip to content

Latest commit

 

History

History
34 lines (31 loc) · 4.24 KB

File metadata and controls

34 lines (31 loc) · 4.24 KB

Catalog of AWS Exploits via SSRF

Server-side request forgery is a class of attack that is not cloud or AWS specific. However, the existence of cloud metadata services, such as IMDS in AWS, have historically allowed for a substantial straightforward impact when SSRF is achieved on a cloud hosted application. For that reason, we include this list of SSRF attacks against AWS environments.

For more about this attack, please see Hacking the Cloud - Steal EC2 Metadata Credentials via SSRF