GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Victor Grenu (zoph@infosec.exchange)

  1. Embed this notice
    Victor Grenu (zoph@infosec.exchange)'s status on Tuesday, 03-Jan-2023 17:39:15 JST Victor Grenu Victor Grenu

    Last week, I discovered a public Amazon S3 bucket belonging to a French bank that contained approximately 16GB of data (122 339 files), including static assets such as CSS, JavaScript, and images, as well as official documents, schema, unverified IBANs and API documentation.

    While the bucket was intentionally left open, the bank's security team promptly responded to my report and corrected the issue.

    However, there are several potential risks associated with leaving an Amazon S3 bucket open to the public.

    By knowing the name of the bucket, I was able to download its entire contents, potentially gain access to sensitive information (naming convention, API endpoints), and even deduce the bank's AWS Account ID (prod?) and AWS Organization ID.

    In today's AWS Security landscape, it is generally considered best practice to use a CloudFront distribution to expose static files rather than leaving S3 buckets open to the public.

    As a fun side note, I discovered that Google was also indexing the bucket's contents.

    Despite the security lapse, the bank was grateful for my report and even rewarded me with a $10 credit as a customer.

    Overall, it was a reminder that security is an ongoing effort, and we should all be vigilant in protecting our assets.

    #AWS #Security

    In conversation Tuesday, 03-Jan-2023 17:39:15 JST from infosec.exchange permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: public.by
      PUBLIC ART Amazing Artists
      from Public
      Public Art Presents Amazing Artists Arts From Across The globe abstract art abstract painting acrylic painting ai weiwei albrecht durer alec monopoly alexander calder alphonse mucha andy goldsworthy andy warhol art art and craft art deco art gallery art nouveau artforkidshub artist artstation artsy artwork ascii art banksy banksy art barbara kruger basquiat bob ross paintings botticelli calligraphy calligraphy letters canvas painting canvas prints caravaggio cezanne claude monet contemporary art cubism dada david hockney de young museum diamond painting digital art doodle art drawing drawing for kids fine art frida kahlo frida kahlo paintings galleries graffiti graffiti art henri matisse In Account jackson pollock james turrell joan miro kandinsky kaws kehinde wiley keith haring Keyword ideas Keywords you provided klimt line art magritte man ray mandala art marcel duchamp marina abramovic mark rothko max ernst mc escher metropolitan museum of art michelangelo modern art monet museum of modern art op art painting paul cezanne paul klee pencil drawing pencil sketch picasso paintings piet mondrian pop art rene magritte rock painting rothko roy lichtenstein sandro botticelli street art surrealism takashi murakami van gogh paintings vincent van gogh wall art warhol wassily kandinsky watercolor painting word art yayoi kusama zentangle zentangle patterns


User actions

    Victor Grenu

    Victor Grenu

    Independent AWS Architect. I draw lines between boxes. | ? Building: unusd.cloud | ? Boutique: zoph.io | ? Running: awssecuritydigest.com

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          84182
          Member since
          3 Jan 2023
          Notices
          1
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.