3 ms·
If v2 requires a token, where is that stored given that the best place to store tenant-specific bootstrapping config is... IMDS?
by danjc 3y ago
If v2 requires a token, where is that stored given that the best place to store tenant-specific bootstrapping config is... IMDS?
- Sayrus 3y agoYou can generate a token on the machine and use a PUT request to set the token. The main difference with IMDSv1 on this is that you now need two requests (One PUT and one GET) instead of a single GET which protects against most SSRF. The 2019 blog post[1] has fairly good explanations on how it works and the threat model. [1] https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service/ https://aws.amazon.com/blogs/security/defense-in-depth-open-...