Assume the Worst: Enumerating AWS Roles Through ‘AssumeRole’
rhinosecuritylabs.com
rhinosecuritylabs.com
The only part of the article that is interesting is the difference in error messages that allows you to confirm whether a role exists or not, but I suspect that wasn't enough content for a blog post so the scary implications of misconfiguring security policies was thrown in.
I think it's quite common for people to just put something in the policy that works on order to quickly proceed with whatever they are doing. Article says they found about 50 policies like this.
This reminds me of the classic enumeration attacks in the 90s where you could figure out usernames in machines by various remote services they had running.
Doing it on AWS global level is kind of cool. :)
Something like this infecting a popular Node.js / Python / Ruby package could potentially do a lot of damage.