Creating a vulnerable S3 instance

In Chapter 7, Reconnaissance – Identifying Vulnerable S3 Buckets, we saw how we can create a vulnerable S3 bucket. It's time to perform those steps again. Let's start by going to Services | S3:

  1. Create a new bucket, name it, and then go to Set permissions
  2. Disable all the settings given in the following screenshot and create the bucket:
Setting permissions
  1. Go to the bucket's Access Control List and allow public read/write access:
Access Control List
  1. Save all the settings

Our vulnerable AWS infrastructure ...

Get Hands-On AWS Penetration Testing with Kali Linux now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.