Retrieving AWS metadata and use it for RCE
When researching a web application, I stumbled upon an endpoint which allowed me to perform SSRF. I’ll use the endpoint
http://example.com/fetch?url=[path] as example.
curl http://example.com/fetch?url=http://169.254.169.254/latest/meta-data/ results in listing the directory contents of the Amazon metadata service.