vulns.co
/
GKData.io MCP

Back to Playbooks

Cloud metadata boundary

Metadata is not the first request. It is a later hop, and only after a callback you control has already shown that the server fetches a URL, and only when the program allows that hop.

Tags: cloud, ssrf, metadata

Level: advanced

Method

  1. Show the fetch first

    Use the SSRF playbook. A DNS or HTTP hit on a callback you control is the proof the server made a request. Until that hit exists, metadata is out.

    Tools: interactsh

  2. Read the program rule

    If the program does not list metadata or link-local targets as allowed, stop at the callback. Write that the next hop was not tested.

    Tools: browser

  3. One allowed hop

    When the program allows it, name the address they allowed and the response you received. Do not walk from that response into other hosts.

    Tools: Burp Suite

  4. Separate it from the bucket

    A public object is the cloud storage playbook. A server-side fetch is the SSRF playbook. This page is only the decision to stop or to take the one allowed hop.

    Tools: browser

Field notes

  • Do not put a metadata address in the report if you were not allowed to request it.
  • A header the metadata service requires is a bypass note on an allowed hop, not a reason to start there.
  • Customer credentials in a metadata response are the impact. Redact them.

References