> For the complete documentation index, see [llms.txt](https://chris26z.gitbook.io/home/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://chris26z.gitbook.io/home/write-ups/cloud-pentesing/ssrf.md).

# SSRF

After getting access to the environment and finding a cloud container doing a basic enumeration, I discovered it is vulnerable to SSRF. Notice in image 1-1 a directory named metadata-db possibly has sensitive information stored there.

<br>

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXffCVRREqSWHgAGoNOUvQOyyiwm_mMAWMHdURvfq_Sz97yQYhB7PMaGBl4nwF76ipDpRtuxhWENwCj5Q_q4Q6ENHUBn4Ohy-tFzbtIg9g9lwl1NpQw4pPUiDnRjCndGgBvqPXOc7oO2kZXZhxIBT0-Cswij?key=izd0szP9MXYIoDke7tpHOQ)

Figure 1-1

\ <br>

In figure 1-2 there's a directory named latest which could mean a version of the container or something involving metadata update.

<br>

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdNt0eap8lHWTUFRHxPwhrDlyDJajA7NDtoGIXC1PvURIf0gcLbU11Yj7PHWYONqWZHco7G2bX8LhGMxchheWIoqdWDn33hDT92BMaXx2lLEh-f8WLpMWAjnG6zfrOvH4umQiJVqS62d-A7flcGtevYRzk?key=izd0szP9MXYIoDke7tpHOQ)

Figure 1-2

<br>

The highlighted text in figure 1-3 shows a directory named secrets which could contain secret keys for the container and gain full control of the container.

&#x20;

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfkAtcM2-KuVH8j0PW58-XNM3gSEsVLj8RwRmyISUBXpRQZEhXxQ46yfuMYjUcPaennG8HrPNNNjtmbB9ZsDO3RB_dNBDAeKiIYJO07Z1WfQYIHXXwF25SHJRRElH7eaCu3Xh9hoYG3z0mMA_wbiNh6fFY?key=izd0szP9MXYIoDke7tpHOQ)

Figure 1-3

\
\
\ <br>

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXf1CCXXIoREfbQWMJ8Cb6eFpPlOA8MIIa57Vu1Jj2KfcFxB5VBoVic1iJjaLcoLACFXIgL5JcbzKvp7ulP2awnNVZwFTyQJjlHUJITCGgDCPIUBl9iYR2adsh5ranNQsEnZ2XCIvg6Sfo154S4SjPMYp3Yo?key=izd0szP9MXYIoDke7tpHOQ)

Figure 1-4

<br>

After i get entered in the kubernetes -goat file which i found in shown in figure 1-4. we get the hash of the container which is shown in figure 1-5

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXeGcp1PUjIwaNGl3TFfiaDGHyNaG9_1VrliSid0m1XQKU-uZFowp5Z47HI4J0uSyPNYnjqtt6niKSbzd4iYjvn6KCCbDERGpNhT7yWkMppRFVJY1kYdpL3lLbvZOM6OGFmQSHYOKIiI0KHJcxYWlAtNbYZo?key=izd0szP9MXYIoDke7tpHOQ)

Figure 1-5

<br>

We can also echo the hash found in kubernetes goat file and decrypt to be readable.

Save for further exploitation if we so choose.

<br>

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXffyKV4Puvsv-BV9IVS7jPtoHn1_TIG_D-kKucPl3aJ0VWbLzzBpwRW1ITq1PfB-bvKecVqkzFNSI6MR--lar4mUUO7f4OxXIPpNN7W46mSX80duFPoSBNalzBl8bbIc5_cRxdJCLIXWBTuMUrZ0SRY5y3u?key=izd0szP9MXYIoDke7tpHOQ)<br>

Figure 1-6

<br>
