Cloud metadata boundary
Metadata is not the first request. It is a later hop, and only after a callback you control has already shown that the server fetches a URL, and only when the program allows that hop.
Tags: cloud, ssrf, metadata
Level: advanced
Method
Show the fetch first
Use the SSRF playbook. A DNS or HTTP hit on a callback you control is the proof the server made a request. Until that hit exists, metadata is out.
Tools: interactsh
Read the program rule
If the program does not list metadata or link-local targets as allowed, stop at the callback. Write that the next hop was not tested.
Tools: browser
One allowed hop
When the program allows it, name the address they allowed and the response you received. Do not walk from that response into other hosts.
Tools: Burp Suite
Separate it from the bucket
A public object is the cloud storage playbook. A server-side fetch is the SSRF playbook. This page is only the decision to stop or to take the one allowed hop.
Tools: browser
Field notes
- Do not put a metadata address in the report if you were not allowed to request it.
- A header the metadata service requires is a bypass note on an allowed hop, not a reason to start there.
- Customer credentials in a metadata response are the impact. Redact them.