4 ms·
I'd be curious to know since C1 is responsible for a popular open source tool for reporting and remediation of AWS configuration, security and otherwise. Look u
by 616c 7y ago
I'd be curious to know since C1 is responsible for a popular open source tool for reporting and remediation of AWS configuration, security and otherwise. Look up cloudcustodian.
That being said, breaking into an instance with a bad S3 role is a foregone conclusion once on that EC2 instance. It will be interesting to learn details.
Common mistake is allowing S3 policies and other IAM policies in general from any was account ID not just "yours" which might explain the TFA and other threads here that indicate the accused somehow has data from other companies not just C1.