isc.sans.edu 8/25/2026, 3:47:35 PM · external

Attackers Use Hostnames to Bypass SSRF Defences on Cloud Metadata

Attackers Use Hostnames to Bypass SSRF Defences on Cloud Metadata
CyberSIXT Evidence Panel Source marked as original reporting

THE article by Johannes Ullrich discusses how attackers can obfuscate IP addresses by using hostnames instead. It highlights the risks associated with Server Side Request Forgery (SSRF) vulnerabilities, specifically referencing attempts to exploit the cloud metadata service IP address 169.254.169.254. The article presents examples of hostnames that attackers might use instead of direct IPs, such as 169.254.169.254.nip.io and others.

The use of tools like 1u.ms allows for the dynamic creation of these hostnames, which complicates detection and mitigation efforts. Ullrich advises maintaining DNS logs to monitor any resolutions tied to these suspicious addresses.

View full article

Article by CyberSIXT