2 ms·
Well, I think I found the problem: despite my meticulously-defined bucket access policy, it turns out I had write permissions enabled for "any authenticated AWS
by benp84 9y ago
Well, I think I found the problem: despite my meticulously-defined bucket access policy, it turns out I had write permissions enabled for "any authenticated AWS user" in my access control list. I did not realize there were two separate pages for these settings.
I suppose it's possible that the bot enabled this setting, but it was probably just me being sloppy :-/ The bot probably scans for poorly-protected S3 buckets that are referenced on websites.
I hope the next victims find this post in a Google search.