Webhook-url-http-3a-2f-2f169.254.169.254-2fmetadata-2fidentity-2foauth2-2ftoken ((link))

Report: Suspicious Webhook URL

The full URL broken down:

for securely validating webhook URLs to prevent these SSRF attacks? How Orca Found SSRF Vulnerabilities in 4 Azure Services Report: Suspicious Webhook URL The full URL broken

2. What is this endpoint?

This is the Azure Instance Metadata Service (IMDS) endpoint used for Managed Identities. Webhook design

Security Analysis Report: Suspicious Webhook URL

Executive Summary

The provided string webhook-url-http-3A-2F-2F169.254.169.254-2Fmetadata-2Fidentity-2Foauth2-2Ftoken decodes to a URL targeting the Azure Instance Metadata Service (IMDS). This is a high-severity security finding indicative of a Server-Side Request Forgery (SSRF) attack attempt, specifically aimed at cloud credential theft. specifically aimed at cloud credential theft.

  • Webhook design