Hacker News new | ask | show | jobs
by opsdisk 930 days ago
If anyone is curious on how this can be abused, here's my "There's no place like 169.254.169.254 - (Ab)using cloud metadata URLs" slides [1] and talk [2] from 2019.

tl;dr - misconfigured reverse proxies allowed cloud metadata URL access across the bigger cloud providers.

[1] https://github.com/opsdisk/cloud_metadata_extractor/blob/mas...

[2] https://www.youtube.com/watch?v=vxReTpBCmh8