S3

S3 holds objects in globally named buckets, and the global namespace is the first weakness: a bucket name is guessable, resolves in DNS, and tells you whether it exists before you hold any credential. Access is decided by three overlapping controls (the account Block Public Access setting, the bucket policy, and object and bucket ACLs), and a misconfiguration in any one exposes data or grants write.

What folds in here#

  • Enumeration: finding buckets and objects by naming, DNS, and permission probing.
  • Public access: buckets left world-readable or world-writable by ACLs or disabled Block Public Access.
  • Bucket policy and ACL: over-broad policies and ACLs that grant cross-account read, write, or takeover.

A writable bucket that backs a website or a software distribution turns into code execution downstream, and a bucket name freed by a deleted resource is reclaimable, covered under dangling-DNS takeover.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more