SSRF(Server Side Request Forgery)ã¨ããèå¼±æ§ãªããæ»æææ³ãæè¿æ³¨ç®ããã¦ãã¾ãã以ä¸ã¯ããã3ã¶æã«SSRFã«ã¤ãã¦è¨åãããè¨äºã§ãã EC2ä¸ã®AWS CLIã§ä½¿ããã¦ãã169.254ã«ã¤ã㦠SSRFèå¼±æ§ãå©ç¨ããGCE/GKEã¤ã³ã¹ã¿ã³ã¹ã¸ã®æ»æä¾ SSRFãå©ç¨ããã¡ã¼ã«éä¿¡ãã¡ã¤ã³ã®ä¹ã£åã ãCODE BLUE 2018ãåå ã¬ãã¼ãï¼å²©éç·¨ï¼ ãã®ã空åã®SSRFãã¼ã ãã«ä¾¿ä¹ãã¦ãSSRFã¨ããæ»æææ³ããã³èå¼±æ§ã«ã¤ãã¦èª¬æãã¾ãã SSRFæ»æã¨ã¯ SSRFæ»æã¨ã¯ãæ»æè
ããç´æ¥å°éã§ããªããµã¼ãã¼ã«å¯¾ããæ»æææ³ã®ä¸ç¨®ã§ããä¸å³ã«SSRFæ»æã®æ§åã示ãã¾ãã æ»æè
ããã¯ãå
¬éãµã¼ãã¼ï¼203.0.113.2ï¼ã«ã¯ã¢ã¯ã»ã¹ã§ãã¾ãããå
é¨ã®ãµã¼ãã¼ï¼192.168.0.5ï¼ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«ã§éé¢ããã¦ããããå¤é¨ããç´æ¥
{{#tags}}- {{label}}
{{/tags}}