Top 10 winner
A deep dive into AWS S3 access controls taking full control over your assets
A deep dive into AWS S3 access controls
Walks every layer of AWS S3 access control, bucket ACL, object ACL and ACP and the AllUsers and AuthenticatedUsers groups, and gives a non-destructive test for each permission. WRITE or WRITE_ACP granted to those groups lets any AWS user overwrite or take ownership of objects, including scripts high-profile sites load from third-party buckets, giving code execution on the victim domain.
Record
- Document
- A deep dive into AWS S3 access controls
- Researcher
- Frans Rosén
- Published by
- Labs Detectify
- Date
- Topic
- Other
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Frans Rosén, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .