S4E just found a high top 10 tcp port service scan
low·Misconfiguration·Updated Dec 16, 2023

AWS bucket with Object listing vulnerability Scanner

Incorrectly configured private bucket containing critical informations like SQL backup.

Est. Time~5 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
22
Times Used
by S4E users
11
Assets Scanned
domains & IPs
12
Vulnerabilities Found
confirmed findings
References
Detail

Amazon S3 provides a simple web services interface that can be used to store and retrieve any amount of data, at any time, from anywhere on the web. Files within S3 are organized into "buckets", which are named logical containers accessible at a predictable URL. Access controls can be applied to both the bucket itself and to individual objects (files and directories) stored within that bucket. A bucket is considered public if any user can list the contents of the bucket, and private if the bucket's contents can only be listed or written by certain S3 users.


Cloud based storage is great but it is very easy to make catastrophic mistakes. If you are setting them up then please ensure you test the access control yourself before uploading any sensitive files.

Solution Advice

Make sure all the Amazon S3 buckets you are using are marked as private and not vulnerable object listing vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.