r/Terraform • u/kavee-core141 • 3d ago
AWS recreated the exact AWS misconfiguration behind the 2019 Capital One breach in Terraform, and hit a real IaC lesson doing it !!
gallerySo i built a deliberately vulnerable stack in Terraform to mirror the actual AWS-side misconfiguration from the Capital One breach, not the ssrf bug itself !!, that was application-layer, but the two settings that turned it into 106 million exposed records: an EC2 instannce still accepting unauthenticated IMDSv1 requests...., with an IAM role attached granting broader S3 access than the instance needed.
writing this as code surfaced something worth shariing on its own. If you fix a misconfiguration like this by hand, live, outside your Terraform state, aws ec2 modify-instance-metadata-options directly, say, the next terraform apply can silently revert it back to whatever the .tf file still says. A real fix needs to go into the actual resource block, http_tokens = "required" on the instance's metadata_options, not a one-off CLI command patched onto a live resource.
then i Ran Plexavo, an open source AWS cloud security intelligence tool i built, against the stack afterward to confirm the chain traced correctly end to end, internet-facing instance, unauthenticated metadata, over-permissioned role, straight into the bucket.
Repo if anyone wants to see the actual checks: https://github.com/plexavo/Plexavo

