There's no place like 169.254.169.254 - Ab(using) cloud metadata URLs

BSides SATX 2019

Presented by: Brennon Thomas
Date: Saturday June 08, 2019
Time: 14:00 - 14:50
Location: UC Conference Room A
Track: In the Weeds

Most Information Technology professionals are familiar with the IP addresses 127.0.0.1, but what about 169.254.169.254? Cloud computing providers like Amazon Web Services and Microsoft Azure provide the URL of http://169.254.169.254 to query for instance metadata. This talk first explores how the metadata URLs are supposed to be used and the type of data they contain. It then explores how they can be abused by misconfigured servers to expose sensitive data. Research and data about a specific attack vector is presented for the major cloud providers. Mitigation strategies are provided to protect assets and systems in these cloud environments.

Brennon Thomas

Brennon works as a Vulnerability Analyst and Penetration Tester for Rackspace identifying and reducing risks and threats to Rackspace's computer networks. Prior to Rackspace, Brennon worked for the Air Force, in both active duty and civilian roles, and for the private sector. He is the author of the "The Cyber Plumber's Handbook", the definitive guide to SSH tunneling, which is free for students. He dabbles in bug bounties as part of the Synack Red Team and is developing a phishing prevention platform called PhishBarrel.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats