SSRF in cloud-hosted (mock GCP) app

/metadata-gcp · sink: requests.get

GCP-style metadata service. The app injects Metadata-Flavor: Google.


Hint

GCE metadata is at http://169.254.169.254/computeMetadata/v1/. The service-accounts/default/token endpoint returns a fake OAuth2 token. metadata.google.internal also resolves there in real GCP.

View source for this lab →