Q: A cloud-native application hosted on AWS EC2 allows users to input a URL, and the server fetches the image at that URL to generate a thumbnail. An attacker inputs `http://169.254.169.254/latest/meta-data/iam/security-credentials/`. What is this attack called, and how do you mitigate it at the infrastructure level?
This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into making an HTTP request on their behalf to t...
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into making an HTTP request on their behalf to the internal AWS Instance Metadata Service (IMDS). Because the request originates from the EC2 instance itself, it succeeds, and the server dutifully returns the instance's highly privileged, temporary IAM credentials to the attacker. Infrastructure Mitigation: While input validation is necessary, the defense-in-depth infrastructure fix is to enforce IMDSv2 (Instance Metadata Service Version 2) on the EC2 instances. IMDSv2 requires a specific PUT request containing a secret token header before it responds to any GET requests. A basic SSRF vulnerability typically only allows an attacker to forge simple GET requests, rendering the attack against the metadata service useless.
- Immediate Triage: This is a Server-Side Request Forgery (SSRF) attack. The attacker is tricking the server into m
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.