During a black-box penetration test you discover that a web application running on an Amazon EC2 instance is vulnerable to server-side request forgery (SSRF). Because you can force the backend to fetch any URL the instance can reach, you attempt to obtain its cloud credentials. Which internal metadata URL would directly return a JSON document containing the instance's temporary AccessKeyId, SecretAccessKey, and Token values?
The Amazon EC2 Instance Metadata Service (IMDS) is exposed at 169.254.169.254. When an instance has an attached IAM role, the path /latest/meta-data/iam/security-credentials/ lists the role names. Appending one of those names-e.g., /latest/meta-data/iam/security-credentials/-causes IMDS to return a JSON document with the role's temporary AccessKeyId, SecretAccessKey, and session Token. Other listed endpoints do not provide these credentials: the parent directory only lists role names, /latest/dynamic/instance-identity/pkcs7 returns a signed identity document, and 169.254.170.2 is the ECS task-metadata address, not present on standard EC2 instances.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is the Amazon EC2 Instance Metadata Service (IMDS)?
Open an interactive chat with Bash
What is an IAM role in AWS and how does it function in this context?
Open an interactive chat with Bash
What makes Server-Side Request Forgery (SSRF) dangerous in cloud environments?
Open an interactive chat with Bash
What is the Amazon EC2 Instance Metadata Service (IMDS)?
Open an interactive chat with Bash
What is the purpose of the IAM role associated with an instance?
Open an interactive chat with Bash
How do SSRF vulnerabilities exploit metadata services?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .