Open cardosec

Case 20B54E · Web AppSec · L3 Applied

Metadata Hits from the PDF Service

Practise as: Incident drill · Interview

Live alertCloudTrail shows the IAM role of pdf-render-prod making ListBuckets calls from an unknown IP at 03:12; app logs show render requests with url=http://169.254.169.254/latest/meta-data/iam/.

Interview questionYou get this alert on call. What do you do in the first hour?

  1. 01 What happened?
  2. 02 What is the impact?
  3. 03 What do you do?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Classify as SSRF-driven credential theft; the role session keys are live off-host and must be treated as compromised
  2. Contain: revoke active role sessions (deny policy with aws:TokenIssueTime condition), block the external IP
  3. Scope: CloudTrail for all actions by that role since first malicious request, especially S3 GetObject and IAM changes
  4. Fix root cause: enforce IMDSv2 (HttpTokens=required), allowlist fetch destinations, block link-local egress
  5. Assess data exposure for notification obligations and preserve logs and the vulnerable request for evidence

If the interviewer pushes back

  • The attacker created a new IAM user before you contained the role. How does that change your response?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.