Skip to content

Commit 83dbcec

Browse files
committed
Add IMDS test cases to unit tests for sinks
1 parent d4ab3a3 commit 83dbcec

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

aikido_zen/sinks/tests/requests_and_urllib3_test.py

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -94,6 +94,14 @@ def ssrf_check(monkeypatch, url):
9494
"http://0x7f.0x0.0x0.0x1:8081/",
9595
# 127.0.0.1 ipv6 mapped
9696
"http://[::ffff:127.0.0.1]:8081",
97+
# Stored IMDS
98+
"http://169.254.169.254/latest/meta-data/iam/security-credentials/",
99+
"http://[fd00:0ec2:0000:0000:0000:0000:0000:0254]:7000/latest/meta-data/iam/security-credentials/",
100+
"http://0xa9.0xfe.0xa9.0xfe/latest/meta-data/iam/security-credentials/",
101+
"http://0xA9FEA9FE/latest/meta-data/iam/security-credentials/",
102+
"http://2852039166/latest/meta-data/iam/security-credentials/",
103+
"http://[::ffff:169.254.169.254]:8081/latest/meta-data/iam/security-credentials/",
104+
"http://[fd00:ec2::254]/latest/meta-data/iam/security-credentials/",
97105
],
98106
)
99107
def test_ssrf_1(monkeypatch, url):

0 commit comments

Comments
 (0)