Skip to content

aws cloud security misconfigurations

1 post with the tag “aws cloud security misconfigurations”

AWS Cloud Security Misconfigurations to Fix First

AWS cloud security misconfigurations shown as an anonymous request listing a public storage bucket next to the account-level block-public-access fix that refuses it

A support page told customers to allowlist a storage hostname so their downloads would work. Nobody thought twice about publishing that hostname, because knowing a name is not the same as having access to it.

Except it was. Asking that hostname for a listing worked from an ordinary browser with no credential offered and none required, and next to the folder the company meant to publish sat one nobody did, full of client records.

Nothing about that bucket was exploited in the traditional sense. A permission that AWS makes off by default was switched on at some point, by someone, for a reason that made sense at the time, and it stayed on because nothing about a misconfigured setting looks different from a correct one until someone asks it the right question.