← All walkthroughs

SSRF to cloud account takeover

A server-side request forgery in a cloud-hosted web app reaches the instance metadata service, steals the attached role's credentials, and pivots into the cloud account.

Cloud-hosted web application Intermediate WebCloudSSRF
Authorized testing only. This is a conceptual, defensive-aware walkthrough that maps an attack path to MITRE ATT&CK, detection and mitigation, and links to references for the detail. It is not a copy-paste playbook. Use it only against systems you own or are explicitly permitted to test.

Scenario

An authorized test of a web application running on a cloud instance. You have identified a server-side request forgery (SSRF) primitive. The objective is to show how a web flaw bridges into the cloud control plane.

Practice this path: OWASP WSTG · Cloud attacks
  1. 1

    Initial Access

    Confirm an SSRF primitive

    Identify an input where the server fetches a URL you control, and confirm you can redirect it to internal addresses rather than only external ones.

    Detection

    Outbound requests from the app to link-local/internal addresses, and fetches to unusual hosts, show in egress and app logs.

    Mitigation

    Validate and allow-list outbound URLs, block link-local ranges, and isolate fetchers.

  2. 2

    Credential Access

    Reach the instance metadata service

    Point the SSRF at the cloud instance metadata endpoint to read the credentials of the role attached to the instance. Where IMDSv2 is enforced, note whether the session-token requirement blocks the naive request — a key finding either way.

    Detection

    Metadata-service access patterns and, for IMDSv2, token requests from the app tier can be monitored; sudden use of instance-role credentials off-host is a strong signal.

    Mitigation

    Enforce IMDSv2 (session tokens, hop limit 1), scope instance roles minimally, and alert on instance-credential use from outside the instance.

  3. 3

    Discovery

    Scope the stolen role

    Use the recovered credentials against the cloud API to learn which services and resources the instance role can access, mapping the blast radius without changing state.

    Detection

    Enumeration API calls from a new IP using instance-role credentials are visible in cloud audit logs.

    Mitigation

    Least-privilege instance roles and alerting on enumeration by workload identities.

  4. 4

    Collection

    Demonstrate impact

    Prove read access to the sensitive cloud storage the role can reach, documenting what could be exposed rather than exfiltrating real data.

    Detection

    Unusual storage reads using instance-role credentials appear in data-plane logs.

    Mitigation

    Scope storage access tightly, encrypt data, and enable data-plane logging.

    References aws-iam-privesc

Key takeaways

  • SSRF plus a permissive instance role turns a web bug into cloud account access.
  • IMDSv2 and a hop limit of 1 defeat the classic metadata-theft path.
  • Least-privilege instance roles shrink the blast radius when a fetcher is abused.