Back to directory
WRITEUP #97

Bucket Monopoly: Breaching AWS Accounts Through Shadow Resources

CloudRCEDoSAccount takeoverInformation disclosure
byYakir Kadkoda
Program
AWS
Published
Aug 9, 2024
Added to HackDex
Aug 14, 2024
Read Full Writeuphttps://www.aquasec.com/blog/bucket-monopoly-breaching-aws-accounts-through-shadow-resources/
RELATED WRITEUPS
Vulnerabilities in Homepage Dashboard
RCESSRF
How 1 Exposed Honeywell API Gave us Control Over an Internal Engineering System
ReconMissing authentication
Unlocking the Weak Spot: Exploiting Insecure Password Reset Tokens
RCEBruteforce
NO_WILDCARD: How I discovered the Organization ID of any AWS Account
ReconInformation disclosure
$500 for Cracking Invitation Code For Unauthorized Access & Account Takeover
RCEOTP bruteforce

Built with ❤️ by Shubham Rawat