4 ms·
Support for your assertion: https://rhinosecuritylabs.com/cloud-security/aws-security-vulnerabilities-perspective/ https://rhinosecuritylabs.com/cloud-security/
by defined 7y ago
Support for your assertion: https://rhinosecuritylabs.com/cloud-security/aws-security-vulnerabilities-perspective/ https://rhinosecuritylabs.com/cloud-security/aws-security-vu...
- jessaustin 7y agoThat's a great link, but they're looking at "misconfigurations". How is that relevant here?
- defined 7y ago> Since the metadata service doesn’t require any particular parameters, fetching the URL http://169.254.169.254/latest/meta-data/iam/security-credentials/IAM_USER_ROLE_HERE http://169.254.169.254/latest/meta-data/iam/security-credent... will return the AccessKeyID, SecretAccessKey, and Token you need to authenticate into the account. They talk about the AWS “Metadata Service” Attack Surface and how juicy a target it is. I was just providing support for that opinion.