Presigned URL

A presigned URL embeds a signature made with your credentials, granting anyone who holds the URL the signed action for its lifetime. You mint presigned access to objects your principal can reach and share or stage it, moving data out without the recipient holding any AWS credentials.

Presign an S3 object#

bash
aws s3 presign s3://<bucket>/<key> --expires-in 604800
# the returned URL downloads the object with no credentials, for 7 days

Exploitation notes#

  • The URL carries your permissions, not the recipient's, so it is a clean exfiltration and sharing primitive.
  • Presigned SageMaker and other service URLs work the same way: a signed, credential-free handle to a privileged action.
  • The signature is valid until it expires or your credentials are revoked, so treat issued URLs as live secrets.

Tools#

  • AWS CLI (s3 presign), boto3 (generate_presigned_url) for arbitrary operations.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more