There's no place like 169.254.169.254 - Ab(using) cloud metadata URLs

Most Information Technology professionals are familiar with the IP addresses 127.0.0.1, but what about 169.254.169.254? Cloud computing providers like Amazon Web Services and Microsoft Azure provide the URL of http://169.254.169.254 to query for instance metadata. This talk first explores how the metadata URLs are supposed to be used and the type of data they contain. It then explores how they can be abused by misconfigured servers to expose sensitive data. Research and data about a specific attack vector is presented for the major cloud providers. Mitigation strategies are provided to protect assets and systems in these cloud environments.

Presented by