CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium
A penetration tester is performing a cloud security assessment. They discover an S3 bucket with a policy that allows `s3:GetObject` for `*` (all principals) but explicitly denies `s3:ListBucket` for `*`. The tester attempts to enumerate the contents of the bucket using `aws s3 ls s3://target-bucket-name` and receives an 'Access Denied' error. However, when the tester attempts to download a known file `report.pdf` using `aws s3 cp s3://target-bucket-name/report.pdf .`, the file downloads successfully. What type of misconfiguration does this indicate?
- APublic write access
- BUnauthenticated read access to objects
- CVulnerable cross-account role assumption
- DServer-Side Request Forgery vulnerability
Show answer & explanationAnswer & explanation
Correct answer: B. Unauthenticated read access to objects
The scenario describes a situation where listing the bucket contents is denied, but individual objects can be downloaded successfully. This indicates that while the ability to enumerate (list) the bucket is restricted, there is unauthenticated read access (`s3:GetObject`) to the actual objects if their names are known or guessed.
Why the other options are wrong
- A. Public write access would allow uploading or modifying files, which is not described.
- C. Cross-account role assumption involves a different set of IAM permissions and is not directly indicated by S3 object access.
- D. SSRF is a web application vulnerability, not an S3 bucket misconfiguration directly.
Public Cloud Storage Misconfiguration (GetObject)
A cloud storage misconfiguration where individual objects are publicly readable (via `GetObject` permission) even if the bucket's contents cannot be listed (via `ListBucket` permission), allowing data exfiltration of known or guessed object names.
- Often results from overly permissive `GetObject` policies.
- Attackers can download files if they can guess the object's path/name.
- Can lead to sensitive data exposure without prior enumeration.
- Distinct from full public read access where `ListBucket` is also allowed.
Memory trick: Buckets can be leaky, especially if GetObject is too easy.