2 ms·
If OP is here, your code block has some html characters double-encoded (> and co). ---- Can someone double check my understanding of something? AWS doesn’t re
by ComputerGuru 3y ago
If OP is here, your code block has some html characters double-encoded (> and co).
----
Can someone double check my understanding of something? AWS doesn’t return the failure reason for auth failure on policy mismatch when access is denied, so you can only know your assumption is correct if the request succeeded.
Does that mean that this only works for resources that have been shared publicly by the upstream owner? If I have an AWS bucket and I only generate signed URLs to access the content and otherwise deny access (standard non-public bucket procedure), this attack wouldn’t work since requests to the base resource need to fulfill both the owner and requester policies and even if your requester policy has a prefix match the upstream access policy will deny the request, no?