Critical vulnerabilities in 6 AWS services disclosed at Black Hat USA
scmagazine.com
scmagazine.com
> If an attacker pre-creates the file with relaxed access permissions, then data stored in the temporary file by the application may be accessed, modified or corrupted by an attacker.
https://owasp.org/www-community/vulnerabilities/Insecure_Tem...
With that said, I definitely ill be looking out for this in the future.
[1] I have unintentionally protected against this by using unique names for my temp files.
The “Shadow Resources” attack vector, which has since been addressed by AWS, stemmed from the automatic generation of S3 buckets by various AWS services, including:
- CloudFormation
- Glue
- EMR
- SageMaker
- ServiceCatalog
- CodeStar
> [...] the researchers note that their findings demonstrate the importance of treating potential identifiers, such as AWS account IDs, as secrets
Which seems to be pretty opposite to the prevailing opinion, at least in some circles. For example the comments here [0] about how to get the account ID for an arbitrary S3 bucket, where many said it was essentially a nothing burger, similar to IP's or emails.
Regardless of who is correct, I think it's a telling example of the "dangers" with identifiers that are kinda-public-kinda-private. I'm guessing at least part of the root cause of this bug are AWS engineer's not thinking about the fact that account ID's aren't fully private.
And s3 buckets are not scoped to an account and their ARN is global and doesn't contain the account id.
For the same reason i advice anybody to always use random suffixes (easily done in Terraform with name_prefix) when generating bucket names.
Never used AWS, but how does it handle auth for data plane operations then?
That’s basically the logic at play here, covered in an Orwellian veneer of “responsibility”.
Unsuspecting users.
When you don’t give companies a chance to fix a vulnerability that could have serious consequences for users, you’re effectively putting the users in harm’s way by disclosing it to the public. Bad actors will take advantage of that information very quickly. Nothing good comes out of that.
Whether you like the company or not, remember that the users have no idea they’re at risk.
Basically something is stateful that shouldn't be, probably because it's built on Lambda.