云ssrf

https://book.hacktricks.xyz/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf

奇安信攻防社区-云上的ssrf利用

https://github.com/Prinzhorn/cloud-metadata-services

SSRF -> EC2 Metadata API -> IAM临时Security Token -> AWS SSM -> RCE

SSRF -> EC2 Metadata API -> IAM临时Security Token -> AWS Lambda -> RCE

SSRF -> EC2 Metadata API -> IAM临时Security Token -> AWS S3 -> 信息泄漏

RCE -> EC2 Metadata API -> IAM临时Security Token -> AWS EC2/S3/Lambda

RCE -> EC2 Metadata API -> EC2 Userdata -> 敏感凭证 ->  其他EC2或者云服务

猜你喜欢

转载自blog.csdn.net/SHELLCODE_8BIT/article/details/134955728