Case C6EF0C · Cloud · L3 Applied
Instance Metadata and IMDSv2
Practise as: Explain it · Interview · Deep dive
Interview questionWhy did SSRF vulnerabilities become so dangerous in AWS, and what does IMDSv2 change?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- The metadata service at 169.254.169.254 hands the instance role credentials to anything that can query it
- An SSRF bug lets an attacker make the server fetch that URL and return live cloud credentials (Capital One, 2019)
- IMDSv2 requires a session token obtained via a PUT with a custom header, which simple SSRF cannot perform
- Hop limit 1 blocks bridged containers; EKS tooling often sets 2 so pods reach IMDS, so keep 1 unless pods need it
- Enforce IMDSv2 as required account-wide and alert on instance credentials used from outside AWS
If the interviewer pushes back
- GuardDuty can flag instance credentials used externally. How does it know?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.