Labs · Cyber Security
Lab: Keep an S3 Bucket Private with Block Public Access and Share One File Safely with a Presigned URL
Course: Cyber Security · Chapter 14: Amazon S3: Buckets, Objects, Policies and Presigned URLs
Chapter 14 covers buckets, objects, policies and presigned URLs; this lab shares a file without making anything public.
Chala mitrano! Many data leaks in the news are simply S3 buckets made public by mistake. Today we keep the bucket fully private and still share one file with a friend, using a link that expires by itself in five minutes. Private by default, share only what is needed. Ekdum professional!
चला मित्रांनो! बातम्यांमधले बरेच data leaks म्हणजे फक्त चुकून public केलेले S3 buckets. आज आपण bucket पूर्ण private ठेवणार आणि तरीही एका मित्राला एक file share करणार, अशा link ने जी पाच मिनिटांत आपोआप expire होते. Default private, फक्त गरजेचं share. एकदम professional!
चलो दोस्तों! खबरों में आने वाले कई data leaks बस गलती से public किए गए S3 buckets होते हैं। आज हम bucket पूरी तरह private रखेंगे और फिर भी एक दोस्त को एक file share करेंगे, ऐसे link से जो पाँच मिनट में अपने आप expire हो जाता है। Default private, सिर्फ ज़रूरत भर share। बिल्कुल professional!
Suppose we are…
Suppose we work at a Policybazaar-style insurance start-up. A customer needs a copy of their policy PDF. The quick but dangerous way is to make the bucket public. The safe way is a presigned URL: a normal-looking link with a signature and an expiry time, created with our own permissions, that works for only one file and only for a few minutes. Everyone else still gets Access Denied.
Goal of this lab
By the end you will have:
- A new bucket with Block all public access on.
- Seen the plain object URL return
AccessDenied. - Shared one file with a 5-minute presigned URL, from the console and from CloudShell, and seen it expire.
What you need (all free)
- Your AWS account (Free Tier), signed in as an IAM user with S3 permissions.
- A small harmless file, for example
sample-policy.txtwith one line of text. Never use a real personal document. - 25–30 minutes.
Safety and ethics
Do not upload real ID cards, bank statements or customer data to practice buckets. Never switch off Block Public Access to "make sharing easier". Delete the bucket at the end of the lab.
Steps
- Open the S3 console and click Create bucket.
- Bucket type: General purpose. Bucket name: something unique such as
yourname-lab-private-2026. Region: Asia Pacific (Mumbai) or your usual Region. -
Keep Object Ownership: ACLs disabled and keep Block all public access ticked. Keep default encryption (SSE-S3). Click Create bucket.
What you should see: the bucket in the list with Access: Bucket and objects not public.
-
Open the bucket → Upload → Add files → choose
sample-policy.txt→ Upload → Close. -
Click the file name. Copy the Object URL (it looks like
https://yourname-lab-private-2026.s3.ap-south-1.amazonaws.com/sample-policy.txt) and open it in a private/incognito window.What you should see: an XML page with
<Code>AccessDenied</Code>. Good: the file is private. -
Back on the object page, click Object actions → Share with a presigned URL. Set 5 minutes, click Create presigned URL, then Copy presigned URL.
-
Paste the link in the private window.
What you should see: the text of your file. The address contains
X-Amz-Expires=300andX-Amz-Signature=.... -
Now make one from the command line. Click the CloudShell icon (
>_) in the console's top bar and run (use your bucket name):aws s3 presign s3://yourname-lab-private-2026/sample-policy.txt --expires-in 120What you should see: one long
https://...X-Amz-Expires=120...link. It works for 2 minutes. -
Wait 2 minutes and open the CloudShell link again.
What you should see:
<Code>AccessDenied</Code>and<Message>Request has expired</Message>. -
Check the bucket is still private: bucket → Permissions tab → Block public access (bucket settings): On, and Bucket policy: No policy.
Ravindra Bagale's Tip
A presigned URL works for anyone who has the link until it expires. So share it only by a private channel, keep the time short, and never paste it in a public WhatsApp group. Short time, right person. Bas!
Ravindra Bagale's Tip – मराठी
Presigned URL expire होईपर्यंत link असलेल्या कोणासाठीही चालते. म्हणून ती फक्त private channel ने share करा, वेळ कमी ठेवा, आणि public WhatsApp group मध्ये कधीच paste करू नका. कमी वेळ, योग्य व्यक्ती. बस!
Ravindra Bagale's Tip – हिंदी
Presigned URL expire होने तक link रखने वाले किसी के भी लिए काम करता है। इसलिए उसे सिर्फ private channel से share करो, समय कम रखो, और public WhatsApp group में कभी paste मत करो। कम समय, सही व्यक्ति। बस!
Common mistakes
| Mistake | What happens | Fix |
|---|---|---|
| Unticking Block Public Access to share one file | The bucket can become public with one wrong policy | Keep it on; use presigned URLs |
| Setting the expiry to 7 days for convenience | The link keeps working if it is forwarded | Use minutes or hours, not days |
| Expecting the presigned link to keep working after your access keys are deleted | It stops early | A presigned URL lives only as long as the credentials that signed it |
| Uploading real personal documents for practice | Real data at risk | Use a sample text file |
| Leaving the bucket after the lab | Small storage charges later, clutter | Empty and delete it (clean-up below) |
Self-check checklist
0 of 5 done
Try-at-home challenge
In CloudShell, list the Block Public Access settings of your bucket with the AWS CLI. Which four settings do you see, and what should each one be?
Check your answer
aws s3api get-public-access-block --bucket yourname-lab-private-2026
You see BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy and RestrictPublicBuckets. For a private bucket all four should be true.
Clean up to avoid charges
- S3 → select your bucket → Empty → type
permanently delete→ Empty. - Select the bucket again → Delete → type the bucket name → Delete bucket.
- Close CloudShell (it is free; nothing to delete).
Samjla ka? Bucket private, link signed, time short, and delete after. Aata pudhe jaauya: Chapter 15 keeps a database private too.