[http] Allow issuing requests with an explicitly specified HTTP method The design of IMDSv2 within both AWS and Alibaba Cloud requires the client to obtain a temporary token via an HTTP PUT request. There is no authentication on this request and there is no associated request body: the requirement to use PUT exists solely to reduce the attack surface for SSRF attacks (since vulnerable servers are much more likely to be able to be tricked into issuing a GET request than a PUT request). iPXE can currently issue requests using HTTP GET (if the request body is empty) or HTTP POST (if the request body includes form parameters). There is no support for issuing a PUT request, or for allowing a script to explicitly specify the HTTP method. Add a "--method" option to the "params" command to allow an arbitrary request method name to be specified, and use this as the HTTP request method. Signed-off-by: Michael Brown <mcb30@ipxe.org>
iPXE is the leading open source network boot firmware. It provides a full PXE implementation enhanced with additional features such as:
boot from a web server via HTTP or HTTPS,
boot from an iSCSI, FCoE, or AoE SAN,
control the boot process with a script,
You can use iPXE to replace the existing PXE ROM on your network card, or you can chainload into iPXE to obtain the features of iPXE without the hassle of reflashing.
iPXE is free, open-source software licensed under the GNU GPL (with some portions under GPL-compatible licences).
You can download the rolling release binaries (built from the latest commit), or use the most recent stable release.
For full documentation, visit the iPXE website.