Amazon S3 Bucket Security issue
-
I received this email from amazon s3. I suppose everyone uses s3 had received this.
My thinking is – ‘it is ok’ because if debug info is switched off, the bucket url is not discoverable – except if malicious port scan against amazonaws.com.
What is your thought on this?
It will be good if authentication (signed url) is used.from Amazon:
We’ve noticed that your Amazon S3 account has a bucket where your permissions allow anonymous requestors to perform READ operations, enumerating the contents of the bucket. Amazon S3 buckets are private by default. Recently, some tools and scripts have emerged which scan services like Amazon S3 and enumerate objects in publicly listable buckets. These tools could be used to identify objects in your bucket. The use of these tools against your buckets may also produce unintended charges in your account.
- The topic ‘Amazon S3 Bucket Security issue’ is closed to new replies.