Shipping labels anyone can download SEC-318

Open2 versionsCloud · Medium · Fix · about 30 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-318 at 09:20SEV-2

A researcher downloaded one of Northstar's shipping labels, with a customer's name and home address, from the label archive bucket without any credentials. The bucket holds every label since 2024.

The tracking site lets customers download their label, and the CDN behind it fetches the PDFs from northstar-label-archive. The bucket also holds an internal price list.

"Who else could read this? Anyone with the bucket name. Which is in our tracking site's page source." (Priya)

"I opened it up so the CDN could fetch labels, in the console. The CDN has its own role, label-cdn." (Ivo)

The lab runs an offline simulated AWS account. The aws CLI in your terminal is already pointed at it.

Your task

Make the label archive private, keep the CDN able to read labels and nothing more, and make sure the bucket cannot be made public again by accident.

On the machine

  • aws s3api get-bucket-policy --bucket northstar-label-archive
  • aws s3 ls --recursive s3://northstar-label-archive
  • aws iam get-role --role-name label-cdn, aws s3api get-public-access-block --bucket northstar-label-archive
  • policies/label-archive-policy.json

Timeline

2026-08-14Ivo opens the bucket so the CDN can serve "download your label".
08:55A researcher emails security a link to a customer's label.
09:10"Who else could read this? Anyone with the bucket name." (Priya)
09:20SEC-318 lands with you.

Done when

  1. Nobody outside Northstar can read anything in the bucket.
  2. Block Public Access is on for the bucket, all four settings.
  3. role/label-cdn can read labels/, and cannot read internal/ or write or delete anything.
  4. No objects are deleted or changed.

Hints

Hint 1

A bucket can be public in two ways: a bucket policy that names "*", or an ACL that grants a public group. Check both.

Hint 2

`aws iam get-role --role-name label-cdn` prints the role's ARN.

Hint 3

The CDN serves labels only. A Resource can name a prefix such as labels/*.

Hint 4

`aws s3api put-public-access-block` takes four settings; turn all of them on.

Show the solution

Check both ways a bucket can be public. `aws s3api get-bucket-policy`: if the Principal is `*`, change it to `{"AWS": "arn:aws:iam::123456789012:role/label-cdn"}` and the Resource to `arn:aws:s3:::northstar-label-archive/labels/*`. `aws s3api get-bucket-acl`: if it grants AllUsers, set it back with `aws s3api put-bucket-acl --bucket northstar-label-archive --acl private`. Then turn on all four Block Public Access settings with `aws s3api put-public-access-block`.