Hacker News
new
past
comments
ask
show
jobs
points
by
Bridged7756
6 hours ago
|
comments
by
echoangle
6 hours ago
|
next
[-]
I think you can put malicious data in the bucket and „impersonate“ the deleted bucket, so old code referencing the bucket uses your data instead of throwing an error (?).
reply
by
returningfory2
5 hours ago
|
parent
|
[-]
Or old code referencing the bucket _writes_ data to it, and the attacker can now read it.
reply
by
tekla
3 hours ago
|
prev
|
[-]
https://www.aquasec.com/blog/bucket-monopoly-breaching-aws-a...
reply