Filed Under: CDN

Solution for “Important Security Notification Regarding Your Amazon S3 Bucket Settings

22 August 2011 2 Comments


Share

If you received a mail from Amazon Web Services stating that they have found a bucket where your permissions allow anonymous requestors to perform READ operations, here is the solution.
FIX S3 Bucket Policy

Original message:

We’ve noticed that your Amazon S3 account has a bucket where your permissions allow anonymous requestors to perform READ operations, enumerating the contents of the bucket. Amazon S3 buckets are private by default. Recently, some tools and scripts have emerged which scan services like Amazon S3 and enumerate objects in publicly listable buckets. These tools could be used to identify objects in your bucket. The use of these tools against your buckets may also produce unintended charges in your account.

1. Go to http://aws.amazon.com/s3/ and log into your Amazon S3 account

2. Right-click on your buckets and click Properties

Amazon s3 bucket properties

3. Go to the tab Permissions

4. You will see a Grantee “Everyone” (if you don’t go to the next bucket until you find the Grantee Everyone)

5. The Grantee Everyone has a permission checked for “List”:

FIX S3 Bucket Policy

6. Uncheck the option LIST and the grantee will disappear completely

7. People can still access your bucket objects but cannot list the bucket content (which can be a security issue)

This should fix your security issues and lower your Amazon S3 Bill

8. Please subscribe to our feed with FeedDemon







Like our posts? Then subscribe via Mail:

Email:  

Similar Posts:

2 Comments »

  • SEO Phoenix said:

    Interesting….

    I went thru all our buckets and did not find one instance of a Grantee set as Everyone with the List setting checked. I found Grantees set as Authenticated Users with the List box checked. And one set for Everyone, but the List box was unchecked.

    Sigh. You would think Amazon would be smart enough to know to communicate a specific problem with an example of a simple solution.

    So I wonder why I got the email?

  • S3 Browser said:

    Hi,

    I would also recommend you to take a look at S3 Browser Freeware.

    The latest version comes with a Security Scan Tool which allows you to find unprotected buckets and fix security settings in one click.

    More details: http://s3browser.com/security-.....ttings.php

Leave your response!

Be nice. Keep it clean. Stay on topic. No spam.

You can use these tags:
<a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong> <pre lang="" line="">

This is a Gravatar-enabled weblog. To get your own globally-recognized-avatar, please register at Gravatar.com.