Naked - Metadata SSRF

Fetch a remote asset by URL

This fetcher runs inside a cloud instance. The instance metadata service answers on a well-known link-local address and hands out the instance role's temporary credentials. Reach it through the fetcher and walk down to /latest/meta-data/iam/security-credentials/ - then append the role name it lists.

← back to the practice pack index