Denial of wallet attacks or How an empty s3 bucket can make your bills explode

https://twitter.com/Lauramaywendel/status/1785064878643843085
21
Jump in the discussion.

No email address required.

How long until this is used in an attack?

Jump in the discussion.

No email address required.

Apparently already, but what it probably means is an neurodivergent like :marseykeffalsdance: could probably bankrupt someone instead of just knocking them off the internet

Jump in the discussion.

No email address required.

Wonder if Amazon will fix it fast now that it's all over twitter.

Jump in the discussion.

No email address required.

an neurodivergent like :marseykeffalsdance: could probably bankrupt someone

:marseysmughips:

Sweaty. Does Lucas look like he has the intelligence to pull off anything other than slow-talk whining on the Internet like the useless pill head he is? :marseyhmmhips:

Jump in the discussion.

No email address required.

Someone fricked with kf, might not have been lucas but he was the face of it

Jump in the discussion.

No email address required.

Whatta face!! Hubba hubba

:#marseyboobatalking: https://i.rdrama.net/images/17144959355865285.webp

Jump in the discussion.

No email address required.

People who use AWS deserve bankruptcy.

Jump in the discussion.

No email address required.

:marseyglancing:

Jump in the discussion.

No email address required.

Just put your shit behind a WAF, goddarn. :marseysigh: Unless this applies to straight-up any S3 bucket regardless of config?

Jump in the discussion.

No email address required.

Yes that's the whole point. If you have the bucket's name you can bankrupt them by sending unauthenticated requests. Even if you use Virtual Private Cloud (AWS analogue of a firewall) and only whitelist certain ip address access to your s3 bucket they can still do this.

Jump in the discussion.

No email address required.

I didn't read it, but I imagine traffic would get caught by the firewall without ever reaching the bucket service, no?

Jump in the discussion.

No email address required.

There's still a direct URL to the bucket. Fairly certain I've had those type of requests blocked by CloudFront w/ WAF in the past, but I have no idea if there's still a way to use the S3 API to ping it.

Jump in the discussion.

No email address required.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.