Protect Amazon S3 Buckets from Unauthorized Access
CS Browser
Free Windows client for Amazon S3 and Amazon S3 compatible storage services
 
Follow

Protect Amazon S3 Buckets from Unauthorized Access

Amazon S3 Bucket Security Overview

Many Amazon S3 users have received security notifications from Amazon about bucket security settings:

Important Security Notification regarding your Amazon S3 bucket settings

We've noticed that your Amazon S3 account has a bucket where your permissions allow anonymous requestors to perform READ operations, enumerating the contents of the bucket. Amazon S3 buckets are private by default. Recently, some tools and scripts have emerged which scan services like Amazon S3 and enumerate files in publicly listable buckets. These tools could be used to identify files in your bucket. The use of these tools against your buckets may also produce unintended charges in your account. <...>

This means that one or more buckets may allow anonymous users to list their contents.

Fortunately, public access can be disabled for the affected buckets. CS Browser includes the Security Scan Tool to find potentially unprotected buckets and fix the discovered issues.

How to Find Unprotected Buckets

  1. Click Tools > Security Scan..

    Tools menu with Security Scan selected
    Click Tools > Security Scan..
  2. The Security Scan Tool dialog opens and the scan starts automatically.

    Security Scan Tool scanning Amazon S3 bucket settings
    Security Scan Tool checks Amazon S3 bucket security settings

    CS Browser retrieves the bucket list and checks the security settings for each bucket. The scan detects public access granted through bucket ACLs to All Users or Authenticated Users, as well as public bucket policies that are not blocked by the current Amazon S3 Block Public Access settings. All discovered issues are displayed in the table.

How to Fix Bucket Security Issues

Review each issue before applying the fix. Some buckets are intentionally public, for example, buckets that host public downloads. The fix blocks public access to every selected bucket.

  1. Select the buckets whose security settings you want to fix, then click Fix selected issues.

    Select unprotected buckets and click Fix selected issues
    Select the buckets and click Fix selected issues
  2. CS Browser enables all four bucket-level Amazon S3 Block Public Access settings and marks the processed buckets in green.

    Amazon S3 bucket security issues fixed
    The selected bucket security issues have been fixed

    Existing ACL grants and bucket policies are not deleted. They remain configured, but cannot grant public access while the corresponding Block Public Access settings remain enabled.

CS Browser 13.5.5 Freeware
Powered by Amazon Web Services and Rated by CNET Editors!
Social Connection
 
People like CS Browser!
People like us
Our customers say

"CS Browser is an invaluable tool to me as a web developer to easily manage my automated site backups" -Bob Kraft, Web Developer

"Just want to show my appreciation for a wonderful product. I use CS Browser a lot, it is a great tool." -Gideon Kuijten, Pro User

"Thank You Thank You Thank You for this tool. A must have for anyone using Amazon S3!" -Brian Cummiskey, USA

Related Products
RdpGuard
protects your Windows Server from RDP Brute-force Attacks.
CS Browser is developed by Netsdk Software FZE and is not affiliated with, endorsed by, or sponsored by Amazon or AWS. Amazon S3 and Amazon S3 Glacier are trademarks of Amazon.com, Inc. or its affiliates.
Copyright © 2008-2026 Netsdk Software FZE. All rights reserved.  Terms of Use.  Privacy Policy.  Mount Amazon S3 Bucket.  RDP brute-force protection.