Open cardosec

Case C6EF0C · Cloud · L3 Applied

Instance Metadata and IMDSv2

Practise as: Explain it · Interview · Deep dive

Interview questionWhy did SSRF vulnerabilities become so dangerous in AWS, and what does IMDSv2 change?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. The metadata service at 169.254.169.254 hands the instance role credentials to anything that can query it
  2. An SSRF bug lets an attacker make the server fetch that URL and return live cloud credentials (Capital One, 2019)
  3. IMDSv2 requires a session token obtained via a PUT with a custom header, which simple SSRF cannot perform
  4. Hop limit 1 blocks bridged containers; EKS tooling often sets 2 so pods reach IMDS, so keep 1 unless pods need it
  5. Enforce IMDSv2 as required account-wide and alert on instance credentials used from outside AWS

If the interviewer pushes back

  • GuardDuty can flag instance credentials used externally. How does it know?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.