Capital One's SSRF Nightmare: How One Bad URL Stole 100 Million Lives
Picture this: a hacker types a URL. Your server fetches it blindly. Boom—100 million credit apps, SSNs, gone. Capital One's SSRF screw-up wasn't rocket science; it was basic trust gone wrong.
Open Source BeatApr 12, 20264 min read
⚡ Key Takeaways
SSRF via unvalidated URLs directly harvested AWS IAM creds from IMDSv1—no malware needed.𝕏
IMDSv2 + URL allowlisting stops this cold; most breaches skip these basics.𝕏
Cloud vendors profit from fixes—your breach is their business model.𝕏
The 60-Second TL;DR
SSRF via unvalidated URLs directly harvested AWS IAM creds from IMDSv1—no malware needed.
IMDSv2 + URL allowlisting stops this cold; most breaches skip these basics.
Cloud vendors profit from fixes—your breach is their business model.