THANK YOU FOR SUBSCRIBING
Hackers can use public access rights to write files to S3 buckets that are password-protected and store data at the victim's expense.
FREMONT, CA: Light spin, a leader in contextualizing cloud security for cloud and Kubernetes environments that simplifies and prioritizes cloud security, disclosed discovery of a novel cross-account threat exploiting AWS S3 buckets. If used effectively, this attack can significantly impact a company's financial line by allowing unauthorized writing from any AWS account to particular AWS buckets.
While examining examples of S3 buckets employing the usual AWS bucket permissions, Lightspin discovered this potential misconfiguration as part of its ongoing investigation on AWS S3 buckets. Many high-profile attacks took place by misconfigured S3 buckets, like Booz Allen Hamilton's recent exposure of more than 6 million customer accounts and Verizon's recent exposure of 60,000 data belonging to the Department of Defense.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Using AWS Cloudtrail and Config, Lightspin revealed that hackers could write to buckets owned by other accounts while those buckets weren't public. Because even private buckets can have policies that allow access from any AWS account, this is the case. Cross-Account attacks on AWS services are challenging to identify and can go undiscovered for long periods.
"AWS doesn't provide the ability to drill down from a bucket to see the status of all the objects it contains." said Vladi Sandler, CEO of Lightspin. "In order to be sure that objects are "safe," its necessary to go through each object's ACL to check if it is open to the public. We recognize that organizations need better context, so we have developed an open-source scanner that provides exactly this - the visibility and the context to know exactly what objects are publicly accessible, at a glance."
While Lightspin only looked at Cloudtrail and Config, other AWS Services that store their data in S3 buckets by default may also be vulnerable to this misconfiguration attack path, and in those circumstances, read rights may allow.
More in News