Aws Acl Public Buckets
Description
Detects S3 buckets that have dangerous public write permissions configured in their ACLs. When buckets grant WRITE, WRITE_ACP, or FULL_CONTROL permissions to AllUsers group, they become vulnerable to unauthorized modifications or deletions by anyone on the internet.
Detection Strategy
• Scans all S3 buckets in the AWS account
• Checks each bucket's ACL configuration for grants to the AllUsers group (http://acs.amazonaws.com/groups/global/AllUsers)
• Reports a vulnerability if any of these dangerous permissions are found: WRITE, WRITE_ACP, or FULL_CONTROL
• Each vulnerability includes the specific permission that was granted and its location in the ACL configuration
Search for vulnerabilities in your apps for free with Fluid Attacks' automated security testing! Start your 21-day free trial and discover the benefits of the Continuous Hacking Essential plan.If you prefer the Advanced plan, which includes the expertise of Fluid Attacks' hacking team, fill out this contact form.