exploiting-ssrf-to-cloud-metadata - Exploiting SSRF to cloud metadata: reach is critical
Adjudicates whether SSRF primitives reach internal cloud instance metadata endpoints to retrieve credentials and defeat filters.
Tags
Updated: 2026-09-18Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Confirm attacker-steered fetch
- Establish internal reach
- Target cloud metadata endpoint
- Defeat allowlist and parser filters
- Handle blind SSRF confirmation
- Rate and record findings
Inputs
- User-influenced URL or host
- Out-of-band interaction listener
- Target environment metadata specs
Outputs
- Instance role temporary credentials
- Out-of-band interaction logs
- SSRF finding severity record
Requirements
- Authorization to test target infrastructure
