Slide 18
Slide 18 text
Service specific Access Key exploitation
- ECS
You’ll need an SSRF along with arbitrary file read vulnerability or an RCE to
gain access to temporary credentials
curl 169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI
SageMaker Notebooks, CodeBuild, App Runner, Batch etc are built on top
of ECS so the exploitation steps stay the same for them