Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AWS S3 Security #6

Closed
apbreports opened this issue May 31, 2018 · 3 comments
Closed

AWS S3 Security #6

apbreports opened this issue May 31, 2018 · 3 comments

Comments

@apbreports
Copy link

Hi Matteo,

You mentioned this as a solution on AWS S3. How could we ensure no search engines indexed the new folder or anyone was able to get the folder name another way? For example listing the directory.
I want to ensure no one had access to that new folder.
Thanks

@matteobrusa
Copy link
Owner

Folder listing is disabled by default on AWS. Just try it.

@apbreports
Copy link
Author

I can't seem to list and directories so that is good news and I added a robots.txt to prevent search indexing. I was just afraid there was another way a person could list the directories with another tool (excluding browsers). I will keep and eye on the logs during the next weeks to see if there is any activity in that folder. Thanks

@matteobrusa
Copy link
Owner

I wouldn't rely on this approach for critical data, as brute force attack are hard to block.
It was meant as a client-side only protection for the client-side only blogging platform https://github.com/matteobrusa/Tumbless

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants