IMDS, XXE and other abbreviations
|
|
|
|
Hint : |
Open victim.pcap in Wireshark and put a filter to get only HTTP requests and dest ip as AWS EC2 Metadata service IP 169.254.169.254 |
|
Right click on the last instance and select Follow >
HTTP Stream for the below URL |
|
Answer : http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance |
Upon submitting the answer the objective is now
completed and we get 10 coins as well |