April 2019
Intermediate to advanced
508 pages
11h 57m
English
There is already plenty of research out there regarding AWS S3, but from the authenticated side of things, it is a little bit different. When moving into S3 during the exploitation phase, most of the process is built around identifying public resources (buckets/objects) that shouldn't be, but it is also more than that. It is time to review automation built around S3 and to see how it is exploitable, and it also is time to review the contents of the various buckets to see if you can gain further access from what you find.
It can be helpful for a client to know that their developers have access to the X, Y, and Z S3 buckets, and that you found a private SSH key stored in bucket Y, which then led to the compromise ...
Read now
Unlock full access