Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

S3 Bucket Takeover vulnerability #287

Open
nvk0x opened this issue Jul 7, 2024 · 1 comment
Open

S3 Bucket Takeover vulnerability #287

nvk0x opened this issue Jul 7, 2024 · 1 comment

Comments

@nvk0x
Copy link

nvk0x commented Jul 7, 2024

Description

I found an unclaimed s3 bucket was using in file, I claimed the bucket and uploaded poc.

Steps to Reproduce:

  1. Go to this link to check code
  2. S3 bucket name: s3.amazonaws.com/navpi-image is using in index.md file
Screenshot 2024-07-07 at 9 41 33 PM
  1. Click here for POC: https://s3.amazonaws.com/navpi-image/index.html
Screenshot 2024-07-07 at 9 50 16 PM

Fix:

Please remove this S3 bucket from the code or tell me i will delete this bucket from my aws account and claim it.

Impact:

  • Attacker can get navcoin employees private IPs Whenever navcoin developers run this project
  • Attacker can host malicious content on this bucket
@nvk0x
Copy link
Author

nvk0x commented Jul 11, 2024

Hi,

Any update ?
I am removing S3 bucket: s3.amazonaws.com/navpi-image from my aws account, it's costing me

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant