While exploiting an unrestricted server-side request forgery in a web application that runs on an Amazon EC2 instance, you intend to retrieve the instance's temporary AWS credentials. The instance still exposes the original Instance Metadata Service (IMDSv1). Which internal URL should you request through the SSRF so that the response contains the JSON document with AccessKeyId, SecretAccessKey, and SessionToken values?
IMDSv1 is reachable only at the link-local address 169.254.169.254. To obtain temporary AWS credentials, you must query the iam/security-credentials endpoint with the instance's IAM role name appended. The parent path /latest/meta-data/iam/security-credentials/ merely lists the role names; the instance-identity document and user-data endpoints do not contain credentials, and the RabbitMQ URI is unrelated to AWS metadata.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is IMDSv1 and why is it important in cloud environments?
Open an interactive chat with Bash
What is SSRF and how does it work in exploiting services like IMDSv1?
Open an interactive chat with Bash
How does IAM role assignment impact the data retrieved from the IMDSv1 endpoint?
Open an interactive chat with Bash
What is IMDSv1, and how does it differ from IMDSv2?
Open an interactive chat with Bash
What is the IAM role mentioned in accessing the /latest/meta-data/iam/security-credentials?<role-name> endpoint?
Open an interactive chat with Bash
What is Server-Side Request Forgery (SSRF), and why is it relevant to AWS IMDS exploitation?
Open an interactive chat with Bash
Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .