How I got access to Maxlifeinsurance insurance company customer PII INFO by AWS metadata access through SSRF

Hi, everyone

SPECIAL COVID-19 Note:

Story Behind the bug:

Here it goes:

Command used:

So the final command will look like this:

cat vul1.txt vul2.txt vul3.txt | sort -u >> unique_sub.txt

NOW the actual SSRF hunting start:

--

--

Cloud Security Engineer |Security Researcher |Pentester | Bugbounty hunter | Pentration tester | CTF player | topmate.io/santosh_kumar_sha

Get the Medium app

A button that says 'Download on the App Store', and if clicked it will lead you to the iOS App store
A button that says 'Get it on, Google Play', and if clicked it will lead you to the Google Play store
Santosh Kumar Sha (@killmongar1996)

Cloud Security Engineer |Security Researcher |Pentester | Bugbounty hunter | Pentration tester | CTF player | topmate.io/santosh_kumar_sha