ãµã㪠Capital Oneããã®SSRFæ»æã«ãã大è¦æ¨¡ãªæ å ±æ¼ããçãããã¦ãAmazonã¯ã¤ã³ã¹ã¿ã³ã¹ã¡ã¿ãã¼ã¿ã«å¯¾ããä¿è·çã¨ãã¦Instance Metadata Service (IMDSv2) ãçºè¡¨ãããæ¬ç¨¿ã§ã¯ãIMDSv2ãçã¾ããèæ¯ã使ãæ¹ãå¹æãéçã説æããä¸ã§ãSSRF対çã«ãããIMDSv2ã®ä½ç½®ã¥ãã«ã¤ãã¦èª¬æããã SSRFã¨ã¯ SSRFã¯ãä¸å³ã®ããã«ãå¤é¨ããç´æ¥ã¢ã¯ã»ã¹ã§ããªãã¨ã³ããã¤ã³ããã«å¯¾ãã¦ãå ¬éãµã¼ãã¼ãªã©ãè¸ã¿å°ã¨ãã¦ã¢ã¯ã»ã¹ããæ»ææ¹æ³ã§ããSSRF(Server Side Request Forgery)ã®è©³ç´°ã«ã¤ãã¦ã¯éå»è¨äºãSSRF(Server Side Request Forgery)å¾¹åºå ¥éããåç §ãã ããã æçµçãªæ»æç®æ¨ã¯å¤æ§ã§ãããè¿å¹´åé¡ã«ãªã£ã¦ããã®ããã¯ã©ã¦ããµã¼ãã¹ã®ã¤ã³ã¹ã¿ã³ã¹ã»ã¡ã¿ãã¼ã¿ãåå¾ãã
{{#tags}}- {{label}}
{{/tags}}