TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hundreds of exposed Amazon cloud backups found leaking sensitive data

181 pointsby ewoodalmost 6 years ago

11 comments

joncranealmost 6 years ago
I&#x27;ve been working almost exclusively in the AWS space for about 10 years now. Clients anywhere from tiny little three-person consultancies to Fortune 100. Commercial, govcloud, dozens of clients.<p>Never once have I ever found a use case for making public EBS snapshots.<p>Who on Earth is thinking that it is a good idea to take an EBS snapshot and make it public?<p>Note, several of those engagements did involve multiple accounts, and the need to share &#x2F; copy AMIs and&#x2F;or snapshots between accounts. But never making them public.
评论 #20657723 未加载
评论 #20657962 未加载
评论 #20657707 未加载
评论 #20661104 未加载
评论 #20658910 未加载
评论 #20657770 未加载
jedbergalmost 6 years ago
The creator of the first Ubuntu distros for EC2 wrote about the dangers of public EBS snapshots 10 years ago:<p><a href="https:&#x2F;&#x2F;alestic.com&#x2F;2009&#x2F;09&#x2F;ec2-public-ebs-danger&#x2F;" rel="nofollow">https:&#x2F;&#x2F;alestic.com&#x2F;2009&#x2F;09&#x2F;ec2-public-ebs-danger&#x2F;</a><p>He just got notified by AWS a couple days ago about the public snapshot he mentioned in the article.<p>But at least AWS is trying to make things better here by proactively checking for public EBS snapshots and notifying people.
评论 #20658020 未加载
d2mwalmost 6 years ago
Public EBS snapshots are great, and thankfully a design other clouds didn&#x27;t copy. I&#x27;ve found all kinds of stuff in there, including a 900GB Oracle backup of a publicly traded manufacturer&#x27;s accounting system. It doesn&#x27;t require much imagination to understand how this kind of data could be profited from, given relatively low effort<p>It seems unlikely a lot of people didn&#x27;t already know about this, it&#x27;s hard to miss even if you only spend a few days with the EC2 API, and it&#x27;s also quite surprising AWS have yet to correct the design. 90% chance it is mostly a UI problem -- there are no warning labels around snapshotting in the EC2 UI
评论 #20657828 未加载
评论 #20657846 未加载
评论 #20657665 未加载
cfstrasalmost 6 years ago
Oh god, how much I hate articles that don‘t list their sources. Where are the slides from?<p>The talk description is here: <a href="https:&#x2F;&#x2F;www.defcon.org&#x2F;html&#x2F;defcon-27&#x2F;dc-27-speakers.html#Morris" rel="nofollow">https:&#x2F;&#x2F;www.defcon.org&#x2F;html&#x2F;defcon-27&#x2F;dc-27-speakers.html#Mo...</a>
kpeekhnalmost 6 years ago
AWS Trusted Advisor has warned of this since 2017:<p><a href="https:&#x2F;&#x2F;aws.amazon.com&#x2F;about-aws&#x2F;whats-new&#x2F;2017&#x2F;06&#x2F;aws-trusted-advisor-now-checks-for-public-snapshots-of-amazon-elastic-block-store-ebs-and-amazon-relational-database-service-rds-data&#x2F;" rel="nofollow">https:&#x2F;&#x2F;aws.amazon.com&#x2F;about-aws&#x2F;whats-new&#x2F;2017&#x2F;06&#x2F;aws-trust...</a>
AaronFrielalmost 6 years ago
I just checked an EC2 console and I can see 19,356 snapshots created by other users.<p>I am so confused.<p>It would be trivial to make finding a snapshot require knowing a unique ID like an AMI.<p>And, why do I need to be able to search for 1000s of customers&#x27; public snapshots in the EC2 console? What conceivable purpose does that serve except being a giant opsec fail?
评论 #20660046 未加载
评论 #20659904 未加载
评论 #20658507 未加载
snazzalmost 6 years ago
It’s still true that most security issues are caused by human ineptitude, not clever vulnerability-hunting or burning sophisticated zero-days.
评论 #20657656 未加载
评论 #20659479 未加载
chimenalmost 6 years ago
Gotta appreciate the hijack of the back button on techcrunch. Bounce rate too big?
jcimsalmost 6 years ago
FWIW same thing is possible with RDS db snapshots and dbcluster snapshots.
andrewstuartalmost 6 years ago
I had a simple glance in the console and there are like 20,000 exposed ebs snapshots - available for anyone to copy and examine - I think that&#x27;s only for a single region too - switch regions to see more.<p>Amazon should make an emergency decision to make all these private.<p>Sure it will break stuff but I&#x27;d be disappointed if Amazon left what is in effect a security hole open for the sake of backwards compatibility.<p>They should also give me a single click link when I sign in to show me all of my public ebs snapshots and throw it hard in my face when I sign in to the console so I simply cannot avoid seeing them all.<p>I have multiple AWS accounts and I just signed in to try to see if I have any public EBS snapshots and then I realised I would need to search <i></i>every single region in every single account and then select every snapshot one by one<i></i> to find out. That&#x27;s a huge problem. I need a single click to show me every exposed snapshot across every region in my account.<p>UPDATE:<p>I can&#x27;t say for sure if this is 100% right but I think if you sign in to your AWS account, then click on each of these links, you will find if you have public snapshots.<p>Maybe someone else could confirm if this is correct?<p><a href="https:&#x2F;&#x2F;us-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=us-east-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;us-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;us-east-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=us-east-2#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;us-east-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;us-west-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=us-west-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;us-west-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;us-west-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=us-west-2#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;us-west-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;ca-central-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ca-central-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ca-central-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?regi...</a><p><a href="https:&#x2F;&#x2F;eu-central-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=eu-central-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;eu-central-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?regi...</a><p><a href="https:&#x2F;&#x2F;eu-west-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=eu-west-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;eu-west-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;eu-west-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=eu-west-2#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;eu-west-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;eu-west-3.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=eu-west-3#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;eu-west-3.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;eu-north-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=eu-north-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;eu-north-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region...</a><p><a href="https:&#x2F;&#x2F;ap-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-east-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a><p><a href="https:&#x2F;&#x2F;ap-northeast-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-northeast-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-northeast-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?re...</a><p><a href="https:&#x2F;&#x2F;ap-northeast-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-northeast-2#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-northeast-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?re...</a><p><a href="https:&#x2F;&#x2F;ap-northeast-3.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-northeast-3#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-northeast-3.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?re...</a><p><a href="https:&#x2F;&#x2F;ap-southeast-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-southeast-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-southeast-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?re...</a><p><a href="https:&#x2F;&#x2F;ap-southeast-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-southeast-2#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-southeast-2.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?re...</a><p><a href="https:&#x2F;&#x2F;ap-south-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=ap-south-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;ap-south-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region...</a><p><a href="https:&#x2F;&#x2F;me-south-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=me-south-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;me-south-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region...</a><p><a href="https:&#x2F;&#x2F;sa-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=sa-east-1#Snapshots:visibility=public;ownerAlias=self;sort=desc:startTime" rel="nofollow">https:&#x2F;&#x2F;sa-east-1.console.aws.amazon.com&#x2F;ec2&#x2F;v2&#x2F;home?region=...</a>
评论 #20660051 未加载
chovyalmost 6 years ago
<a href="https:&#x2F;&#x2F;fullstacknews.com&#x2F;t&#x2F;devops" rel="nofollow">https:&#x2F;&#x2F;fullstacknews.com&#x2F;t&#x2F;devops</a>