Writing
cloud security
2 articles on this subject.
SSRF past the metadata endpoint: Docker on 2375, kubelet on 10250, and the 50,000 hosts TeamTNT found
IMDSv2 closed the famous SSRF target. The internal network is still full of unauthenticated control planes that will run a container for anyone who asks, and crypto-mining crews have been scanning for them since 2020.
7 min read
SSRF to cloud takeover: what Capital One taught us, and why half of EC2 still has not learned it
One HTTP request to 169.254.169.254 turned an SSRF into 100 million records. Seven years on, IMDSv2 fixes it and adoption is roughly half. How the attack works, why v2 stops it, and how to enforce it.
7 min read