ShieldSyncLABS

LabsS3 misconfiguration & data exposure

← Back to plans

S3 misconfiguration & data exposure

Find and fix common S3 misconfigurations — public buckets, missing encryption, over-broad IAM — in a realistic mini-account, then verify your fixes.

BeginnerFREE~30 min 2 launches over a 24h window · 30 min each

The scenario

A small team shipped fast and left their S3 estate exposed. Two buckets are world-readable, neither enforces encryption or HTTPS, and a service account has s3:* on every resource. Your job: find the problems and fix them in place.

What you'll fix

  • Public buckets — one exposed via a bucket policy, one via an ACL
  • Missing encryption — enforce SSE-KMS on both
  • Non-TLS access — require HTTPS-only
  • An over-broad IAM user — scope s3:* down to least privilege

Each fix is checked live against your account by Check my work.

This is your workspace

Sign in and a real, isolated AWS account spins up — the step-by-step guide opens here, graded against your live fixes.

Sign in & launch — free

No card needed · auto-wiped when you're done