CompTIA PenTest+ (PT0-003)Attacks and ExploitsMedium

A tester runs a cloud reconnaissance tool that enumerates common bucket-naming patterns and discovers an AWS S3 bucket named company-backups configured with public read and write access control lists. The tester downloads sensitive backup files and uploads a test file without authentication. What is this finding an example of?

  1. AIAM role privilege escalation
  2. BInsecure direct object reference
  3. CServer-side request forgery
  4. DPublicly exposed cloud storage misconfiguration
Show answer & explanation

Correct answer: D. Publicly exposed cloud storage misconfiguration

Anonymous read/write access to an S3 bucket is a classic cloud storage misconfiguration, allowing unauthorized data exfiltration and tampering without needing to exploit IAM policies or compute services.

Why the other options are wrong

  • A. IAM privilege escalation involves abusing overly permissive identity policies, not object storage ACLs.
  • B. IDOR relates to application-layer object references, not cloud bucket permissions.
  • C. SSRF involves tricking a server into making requests, unrelated to bucket ACL settings.

Public Cloud Storage Misconfiguration

A security flaw where cloud storage objects (e.g., AWS S3 buckets, Azure Blob containers) are configured with overly permissive access controls, exposing data to the public internet.

  • Tools like S3Scanner or Grayhat Warfare can enumerate open buckets
  • Public read exposes data; public write allows tampering/malware hosting
  • Root cause is misconfigured bucket policies/ACLs, not code vulnerabilities

Memory trick: An open bucket lets anyone dip their hand in

More Attacks and Exploits questions