A presigned URL embeds a signature made with your credentials, granting anyone who holds the URL the signed action for its lifetime. You mint presigned access to objects your principal can reach and share or stage it, moving data out without the recipient holding any AWS credentials.
Presign an S3 object#
aws s3 presign s3://<bucket>/<key> --expires-in 604800
# the returned URL downloads the object with no credentials, for 7 days
Exploitation notes#
- The URL carries your permissions, not the recipient's, so it is a clean exfiltration and sharing primitive.
- Presigned SageMaker and other service URLs work the same way: a signed, credential-free handle to a privileged action.
- The signature is valid until it expires or your credentials are revoked, so treat issued URLs as live secrets.
Tools#
- AWS CLI (
s3 presign), boto3 (generate_presigned_url) for arbitrary operations.