惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
T
Threatpost
C
CERT Recently Published Vulnerability Notes
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Security Archives - TechRepublic
Security Archives - TechRepublic
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
K
Kaspersky official blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
Attack and Defense Labs
Attack and Defense Labs
N
News and Events Feed by Topic
Project Zero
Project Zero
H
Heimdal Security Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
Google Online Security Blog
Google Online Security Blog
W
WeLiveSecurity
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Schneier on Security
Schneier on Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
N
News | PayPal Newsroom
Hacker News - Newest:
Hacker News - Newest: "LLM"
H
Hacker News: Front Page
L
LINUX DO - 热门话题
Spread Privacy
Spread Privacy
T
Threat Research - Cisco Blogs
Cloudbric
Cloudbric
V
Vulnerabilities – Threatpost
Hacker News: Ask HN
Hacker News: Ask HN
S
Securelist
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
TaoSecurity Blog
TaoSecurity Blog
NISL@THU
NISL@THU
N
News and Events Feed by Topic
S
Security Affairs
The Last Watchdog
The Last Watchdog
T
Tor Project blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
T
The Exploit Database - CXSecurity.com
Simon Willison's Weblog
Simon Willison's Weblog
P
Palo Alto Networks Blog
AWS News Blog
AWS News Blog
P
Proofpoint News Feed
C
Cisco Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
L
LINUX DO - 最新话题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
T
Tenable Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
S
Schneier on Security

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
The Bucket You Deleted is Still in Your DNS: S3 Bucket Takeover at Bime
Bala Paranj · 2026-04-25 · via DEV Community

In 2016, a researcher found that a2.bime.io had a CNAME record pointing to bimeio.s3.amazonaws.com. The bucket bimeio did not exist. It was not owned by Bime. It was not owned by anyone.

The researcher created the bucket in their own AWS account. a2.bime.io was now serving their content — under Bime's domain, with Bime's SSL certificate, trusted by Bime's users.

This is HackerOne #121461. The fix was either claiming the bucket name or deleting the CNAME. Either takes under a minute. The window between bucket deleted and researcher claimed it was measured in days.

Why This Attack Requires Nothing

S3 bucket names are globally unique across all AWS accounts. When a bucket is deleted, the name becomes available to any AWS account immediately. If a DNS CNAME still points to that bucket's S3 endpoint, whoever registers the name first controls what the DNS record resolves to.

The attack requires no credentials, no exploit, no social engineering:

# Step 1: find the dangling CNAME
dig a2.bime.io
# a2.bime.io → bimeio.s3.amazonaws.com

# Step 2: check if the bucket exists
aws s3 ls s3://bimeio 2>&1
# NoSuchBucket

# Step 3: register it
aws s3 mb s3://bimeio --region us-east-1
# make_bucket: bimeio

# a2.bime.io now serves your content

Enter fullscreen mode Exit fullscreen mode

Three commands. No special access. The domain is yours until Bime notices.

The Gap Traditional Tools Cannot See

CSPM tools inventory S3 buckets in the organization's AWS accounts. When a bucket is deleted, it disappears from the inventory. The scan finds nothing wrong — because there is nothing in the account to scan. The bucket does not exist.

The DNS record is in Route53 or Cloudflare or a registrar's control panel. It is not an AWS resource. It does not appear in AWS Config. It does not appear in Security Hub. It does not appear in any CSPM finding.

The NoSuchBucket response that a2.bime.io was returning is a valid HTTP response — monitoring does not alert on it. It looks like an outage, not a vulnerability.

The gap sits between two inventories: the AWS account (which has no bucket) and the DNS zone (which has a CNAME). Neither flags the mismatch. The organization has no tool that cross-references DNS records against S3 bucket ownership.

Why Teams Miss This

The sequence is common. A team deploys a feature using S3, sets up the CNAME, ships it. The feature is deprecated. The bucket is deleted. Deleting the bucket is in the AWS console. Removing the CNAME is in the DNS provider — a different system, often a different team. The CNAME removal is a separate task that does not block the deployment and gets forgotten.

Months later, nobody remembers that a2.bime.io exists. It does not appear in any active service inventory. It does not generate any alerts. It sits in the DNS zone file, pointing at nothing, waiting.

The System Invariant

The invariant is precise:

Every DNS CNAME pointing to an S3 endpoint must reference a bucket that exists and is owned by the same organization.

Observable in a snapshot without making any change to the infrastructure: the DNS record points to bimeio.s3.amazonaws.com, the bucket bimeio does not exist in the account inventory, the name is claimable. That is the full finding — no live exploitation required.

What Stave Detects

Stave models the DNS-to-S3 reference as a first-class asset with two properties:

{
  "id": "bime-a2-cname-ref",
  "type": "s3_bucket_reference",
  "properties": {
    "s3_ref": {
      "endpoint": "a2.bime.io",
      "bucket": "bimeio",
      "bucket_exists": false,
      "bucket_owned": false
    }
  }
}

Enter fullscreen mode Exit fullscreen mode

The control evaluates the reference, not the bucket:

id: CTL.S3.BUCKET.TAKEOVER.001
name: Referenced S3 Buckets Must Exist And Be Owned
unsafe_predicate:
  any:
    - field: properties.s3_ref.bucket_exists
      op: eq
      value: false
    - field: properties.s3_ref.bucket_owned
      op: eq
      value: false

Enter fullscreen mode Exit fullscreen mode

Either condition alone fires the control. Both being false — bucket does not exist and is not owned — means the name is available for registration by anyone.

The E2E Test

This report is one of 28 end-to-end tests in Stave's test suite. The test reconstructs the exact Bime configuration — a s3_bucket_reference asset with bucket_exists: false and bucket_owned: false — across two snapshots spanning 8 days, runs stave apply, and compares output byte-for-byte against a golden file.

./stave apply \
  --controls testdata/e2e/e2e-h1-bime-121461/controls \
  --observations testdata/e2e/e2e-h1-bime-121461/observations \
  --max-unsafe 168h \
  --now 2016-03-18T00:00:00Z

Enter fullscreen mode Exit fullscreen mode

Expected output:

Status: NON_COMPLIANT
Finding: CTL.S3.BUCKET.TAKEOVER.001 — bime-a2-cname-ref
  Unsafe for 192 hours (threshold: 168 hours)
  Misconfigurations: bucket_exists=false, bucket_owned=false
Exit code: 3

Enter fullscreen mode Exit fullscreen mode

The test proves that CTL.S3.BUCKET.TAKEOVER.001 detects the exact configuration state that enabled the Bime takeover — not in theory, but by evaluating a reconstructed snapshot against the control predicate with a golden file proving the output.

The Asset Type Distinction

The finding is on bime-a2-cname-ref, not on an S3 bucket. The asset type is s3_bucket_reference — the DNS record that points to S3, not the bucket itself.

This distinction matters. The bucket does not exist in any account. A bucket-level scanner has nothing to evaluate. The vulnerability lives in the reference — the DNS record that points to a name that is no longer owned. Stave models the reference as an asset precisely because the reference creates the risk.

This is the same principle as stave path — Stave reasons about relationships between assets, not just about assets in isolation. A CNAME record and the bucket it points to form a relationship. When the bucket end of that relationship is broken, the CNAME becomes a liability.

Remediation

Two options, both under a minute:

Option A — Claim the bucket name:

aws s3 mb s3://bimeio --region us-east-1

Enter fullscreen mode Exit fullscreen mode

The bucket can be empty. The goal is to claim the namespace before an attacker does. Apply Block Public Access immediately after:

aws s3api put-public-access-block \
  --bucket bimeio \
  --public-access-block-configuration \
    BlockPublicAcls=true,IgnorePublicAcls=true,\
    BlockPublicPolicy=true,RestrictPublicBuckets=true

Enter fullscreen mode Exit fullscreen mode

Option B — Remove the CNAME:

aws route53 change-resource-record-sets \
  --hosted-zone-id ZONE_ID \
  --change-batch '{
    "Changes": [{
      "Action": "DELETE",
      "ResourceRecordSet": {
        "Name": "a2.bime.io",
        "Type": "CNAME",
        "TTL": 300,
        "ResourceRecords": [{"Value": "bimeio.s3.amazonaws.com"}]
      }
    }]
  }'

Enter fullscreen mode Exit fullscreen mode

Option A is faster — no DNS propagation delay. Option B is cleaner — removes the unused reference entirely. Do Option B regardless, because the subdomain should not exist if the bucket is empty.

The process fix:
Before deleting any S3 bucket, search DNS records for references to that bucket name. Remove the CNAME before deleting the bucket.

Checklist

  • Audit DNS zone for CNAMEs pointing to *.s3.amazonaws.com or *.s3-*.amazonaws.com
  • For each: verify the referenced bucket exists and is owned by the account
  • Bucket deletion process includes DNS record cleanup as a required step
  • CTL.S3.BUCKET.TAKEOVER.001 runs in CI on every infrastructure change
  • DNS changes and bucket deletions are correlated in change management

The bucket was deleted. The DNS record was not deleted. The attack was three commands.


HackerOne #121461 — Bime S3 bucket takeover via dangling CNAME. Stave E2E test e2e-h1-bime-121461 reconstructs the vulnerable configuration and verifies detection against a golden file. Stave detects dangling S3 bucket references via CTL.S3.BUCKET.TAKEOVER.001, evaluated from local DNS and S3 inventory snapshots without cloud credentials.