Case 20B54E · Web AppSec · L3 Applied
Metadata Hits from the PDF Service
Practise as: Incident drill · Interview
Live alertCloudTrail shows the IAM role of pdf-render-prod making ListBuckets calls from an unknown IP at 03:12; app logs show render requests with url=http://169.254.169.254/latest/meta-data/iam/.
Interview questionYou get this alert on call. What do you do in the first hour?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Classify as SSRF-driven credential theft; the role session keys are live off-host and must be treated as compromised
- Contain: revoke active role sessions (deny policy with aws:TokenIssueTime condition), block the external IP
- Scope: CloudTrail for all actions by that role since first malicious request, especially S3 GetObject and IAM changes
- Fix root cause: enforce IMDSv2 (HttpTokens=required), allowlist fetch destinations, block link-local egress
- Assess data exposure for notification obligations and preserve logs and the vulnerable request for evidence
If the interviewer pushes back
- The attacker created a new IAM user before you contained the role. How does that change your response?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.