Curl-url-http-3a-2f-2f169.254.169.254-2flatest-2fapi-2ftoken
The most famous attack is the . A former AWS employee exploited an SSRF vulnerability to reach http://169.254.169.254/latest/meta-data/iam/security-credentials/... and retrieved an IAM role with excessive permissions, then exfiltrated 100+ million customer records.
Set --http-put-response-hop-limit 1 so that containers or proxies cannot forward metadata requests. curl-url-http-3A-2F-2F169.254.169.254-2Flatest-2Fapi-2Ftoken
http://169.254.169.254/latest/api/token
If you are a developer or security researcher: The most famous attack is the


