Amazon S3 Security Vulnerability Fix
Already begging for attention for this Amazon S3 CDN phpFox security vulnerability for about 1,5 year now.
Amazon S3 offers authentication and expiring url's to files which is great (read: ESSENTIAL) for membership sites.
This way members from a particular level (like VIP or whatever) can access particular files while other membership levels can not.
Even if USER-A is in a VIP membership he can not share it (videolinks, audiolinks, images, pdf, etc. hosted on S3) with his buddy USER-B as the links are authenticated and self expiring after XX seconds.
Right now if you mirror a phpFox site with offline browser software (such as Teleport) you can index all links to Amazon S3 and literally rip all content even if you're not a member at all.
Imagine the bandwidth costs for the website owner when this vulnerability gets exploited (imagine you're a website owner and host multiple terrabyte of media on S3) and also the privacy settings for users content are totally useless since all images, video's, etc. are easily accessible via Amazon S3.
So even if your members set their content to private and/or password protect it you can easily bypass this protection.
What do we really need?
-. S3 URL Authentication
-. Expiring URL's (admin can set XX seconds/minutes/hours the link is valid. After the set time a page refresh is required to get new url's)
Please note that it is NOT only about simply disabling XML preview that shows all files in the S3 folder.
It goes way way deeper than that and we REALLY need this to get fixed.
Already opened a bugreport about a year ago but then got the standard "working as designed" status.
Clearly to me that people really underestimate this security vulnerability.
So because of that "working as designed" status i try to get this fixed by a "feature request" (while it isn't a feature, but who cares, as long as it get fixed!).





