Definition · Subdomain Enumeration

What is S3 Bucket Exposure?

Amazon S3 stores files in buckets addressed by HTTPS URLs, and the same pattern exists in Azure Blob Storage containers and Google Cloud Storage buckets. Exposure means the access configuration permits anonymous access — most often read and listing, occasionally write — so a bucket’s contents can be enumerated and retrieved by anyone who knows or guesses its name.

How buckets become public

Several mechanisms can grant public access, and they interact:

  • Legacy access control lists granting the “all users” group read or write
  • A bucket policy with a wildcard principal
  • Account or bucket-level public access blocks disabled, which is what allows the above to take effect
  • A bucket deliberately made public to serve website assets, which then accumulates files that should not be public

AWS has progressively tightened the defaults — public access is blocked and ACLs disabled for new buckets — so exposure today is usually an older bucket, an explicit override, or an unmanaged account rather than a fresh mistake.

Why it is found so easily

Bucket names sit in a global namespace and follow guessable patterns: the company name with suffixes like -backups, -assets, -dev, -logs. Names also leak in page source, JavaScript bundles, mobile applications and CT logs when a custom domain is used. A writable bucket serving website content is worse than a readable one, since an attacker can modify what visitors load.

There is a DNS dimension too. A CNAME pointing at a deleted bucket is the classic subdomain takeover scenario — an attacker who registers the freed bucket name serves content on your subdomain.

What to check

Enable account-level public access blocks, review bucket policies for wildcard principals, prefer signed URLs or a CDN with an origin access identity over public buckets, turn on access logging, and remove DNS records when a bucket is retired.

See database exposure and Elasticsearch exposure for the datastore equivalents, plus least privilege, security misconfiguration and asset discovery.

See what your business is exposing

SurfaceLoop checks every internet-facing asset you own across seven risk categories, daily.