SSRF

Cloud Security

Abusing AWS Instance Metadata (IMDS) and SSRF

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Web Exploitation

SSRF Deep Dive: Pivoting to Cloud Metadata, Internal Scans, and Filter Bypass

A practical guide to Server-Side Request Forgery: cloud metadata theft, internal port scanning, filter bypass, and Blue Team defenses.
Web Exploitation

XXE Attacks: Exploiting XML External Entities for File Disclosure and Blind OOB Exfiltration

A practical guide to XML External Entity attacks — DOCTYPE abuse, file disclosure, SSRF, blind/OOB exfiltration, and defense.
Tools & Defense

AWS Security Fundamentals and Attack Techniques: IAM, S3, and the Metadata Service

A practical primer on attacking and defending AWS: IAM enumeration, S3 misconfigurations, IMDS abuse, and Pacu.
Cloud Security

Cloud Metadata Service (IMDS) Attacks via SSRF: Stealing Credentials and Defending IMDSv2

How attackers pivot from SSRF to cloud credential theft through 169.254.169.254, and how IMDSv2 and hop limits stop them.