https://app.hackthebox.com/sherlocks/OpTinselTrace-2
Hack The Box Sherlocksã¨ã¯
Sherlock Scenario
It seems our precious technology has been leaked to the threat actor. Our head Elf, PixelPepermint, seems to think that there were some hard-coded sensitive URLs within the technology sent. Please audit our Sparky Cloud logs and confirm if anything was stolen! PS - Santa likes his answers in UTC...
ç§ãã¡ã®è²´éãªæè¡ãæ»æè ã«æµåºããããã§ããç§ãã¡ã®é ã®ã¨ã«ãã§ãã PixelPepermint ã¯ãéä¿¡ããããã¯ããã¸ã¼å ã«ãã¼ãã³ã¼ãã£ã³ã°ãããæ©å¯ URL ãããã¤ããã£ãã¨èãã¦ããããã§ãã Sparky Cloud ã®ãã°ãç£æ»ãã¦ãä½ããçã¾ãããã©ããã確èªãã¦ãã ããã PS - ãµã³ã¿ãã㯠UTC ã§ã®çãã好ã¿ã¾ã...
2023å¹´ã®Sherlocksã¯ãªã¹ãã¹ã¤ãã³ãåé¡ã®2åç®ã
AWSã®CloudTrailã®ãã°ãã¼ã¿ãä¸ããããã®ã§ã¯ã©ã¦ãã®ãã©ã¬ã³ã¸ãã¯ãé²ãã¦ããã
Tasks
Task 1
What is the MD5 sum of the binary the Threat Actor found the S3 bucket location in?
è å¨ã¢ã¯ã¿ã¼ã S3 ãã±ããã®å ´æãè¦ã¤ãããã¤ããªã® MD5 åè¨ã¯ãããã§ãã?
ä»ã®Taskãå
¨é¨è§£ãã¦ãä¸çªæå¾ã«è§£ããã
è
å¨ã¢ã¯ã¿ã¼ã¯ã©ããããS3ãã±ããã®å ´æãè¦ã¤ããããã§ãS3ãã±ããã®å ´æã¨ã¯å¾è¿°ããpapa-noel.s3.eu-west-3.amazonaws.com
ã®ãã¨ã
VirusTotalã§papa-noel.s3.eu-west-3.amazonaws.com
ãæ¤ç´¢ãã¦ã¿ãã
https://www.virustotal.com/gui/domain/papa-noel.s3.eu-west-3.amazonaws.com/relations
ããã¾ãããããã®Relationsãè¦ã¦ã¿ãã¨é¢é£ã¥ãããã¦ããELFãã¡ã¤ã«ããã£ãï¼
ã»ã¼ãããã§ãã¦ãã
ããã®MD5ããã·ã¥ãéãã¨æ£çã
62d5c1f1f9020c98f97d8085b9456b05
Task 2
What time did the Threat Actor begin their automated retrieval of the contents of our exposed S3 bucket?
è å¨ã¢ã¯ã¿ã¼ã¯ãå ¬éããã S3 ãã±ããã®å 容ã®èªååå¾ãéå§ããã®ã¯ãã¤ã§ãã?
papa-noel.s3.eu-west-3.amazonaws.com
ã®ãã¡ã¤ã«ã¢ã¯ã»ã¹ãå
ã«å¤å®ããã
ãã©ã¦ã¶ããã¢ã¯ã»ã¹ããå ´å㯠favicon.ico
ã¸ã®ã¢ã¯ã»ã¹ãä¼´ãã®ã§ãããç¡ããã°èªåã§åå¾ããã¦ããã¨å¤æã§ããã
æéå·®ãèæ
®ããã¨.gitãã©ã«ãã®ãã¡ã¤ã«ããã¦ã³ãã¼ããå§ããã¿ã¤ãã³ã°ãçãã
2023-11-29T08:24:07Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/COMMIT_EDITMSG'} 2023-11-29T08:24:07Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/config'} 2023-11-29T08:24:07Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/description'} 2023-11-29T08:24:07Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/HEAD'} 2023-11-29T08:24:07Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/applypatch-msg.sample'} 2023-11-29T08:24:08Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/commit-msg.sample'} 2023-11-29T08:24:08Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/fsmonitor-watchman.sample'} 2023-11-29T08:24:08Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/post-update.sample'} 2023-11-29T08:24:08Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-applypatch.sample'} 2023-11-29T08:24:09Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-commit.sample'} 2023-11-29T08:24:09Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-merge-commit.sample'} 2023-11-29T08:24:09Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-push.sample'} 2023-11-29T08:24:09Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-rebase.sample'} 2023-11-29T08:24:09Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/pre-receive.sample'} 2023-11-29T08:24:10Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/prepare-commit-msg.sample'} 2023-11-29T08:24:10Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/push-to-checkout.sample'} 2023-11-29T08:24:10Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/hooks/update.sample'} 2023-11-29T08:24:10Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/index'} 2023-11-29T08:24:10Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/info/exclude'} 2023-11-29T08:24:11Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/logs/HEAD'} 2023-11-29T08:24:11Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/logs/refs/heads/master'} 2023-11-29T08:24:11Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/38/938fa8723c40cedfb7819340563c81961d7712'} 2023-11-29T08:24:11Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/5d/24a8f411fc931b54fb9a4b58b6b55f1016c34d'} 2023-11-29T08:24:12Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/62/13ad5b238260339ce346bf8f9063a8559c538a'} 2023-11-29T08:24:12Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/69/a6bf0c5763a8cfc8d52d123e29986441869eab'} 2023-11-29T08:24:12Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/6e/e67e3c147c7b310ea95271f07165056a84a1aa'} 2023-11-29T08:24:12Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/8f/3ebb72ee80ee21f35e64ff2040ffbfb8d78d90'} 2023-11-29T08:24:13Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/99/9775de5661604d8b3e7b5929d1fd1818db40ac'} 2023-11-29T08:24:13Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/99/dbe4b3d52641ecb95dc3361bc7c324ba20f8e1'} 2023-11-29T08:24:13Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/a9/2e975c8c52221d5c1c371d5595f65eb13f8be5'} 2023-11-29T08:24:13Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/d5/4035991ea077b39062f858dfab56ea4fc1eb32'} 2023-11-29T08:24:13Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/da/4d9a7c2824a50b8615b0149da53df83e812529'} 2023-11-29T08:24:14Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/backup.py'} 2023-11-29T08:24:14Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/check.js'} 2023-11-29T08:24:14Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/f1/3ae004942c081e8a345a35bc4c1a006fb9a9d6'} 2023-11-29T08:24:14Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/objects/ff/46564b94ef03aca8f76224d3286e7e608276e4'} 2023-11-29T08:24:14Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/refs/heads/master'} 2023-11-29T08:24:15Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/claus.py'} 2023-11-29T08:24:15Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/disk.ps'} 2023-11-29T08:24:15Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/organise.rb'} 2023-11-29T08:24:15Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/santa_journey_log.csv'} 2023-11-29T08:24:16Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/update.sh'} 2023-11-29T08:24:16Z | {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'santa-list.csv'}
ãã2023-11-29 08:24:07
ãçãã
Task 3
What time did the Threat Actor complete their automated retrieval of the contents of our exposed S3 bucket?
è å¨ã¢ã¯ã¿ã¼ãå ¬éããã S3 ãã±ããã®å 容ã®èªååå¾ãå®äºããã®ã¯ä½æã§ãã?
Task 2ããåããã2023-11-29 08:24:16
ãçãã
Task 4
Based on the Threat Actor's user agent - what scripting language did the TA likely utilise to retrieve the files?
è å¨ã¢ã¯ã¿ã¼ã®ã¦ã¼ã¶ã¼ ã¨ã¼ã¸ã§ã³ãã«åºã¥ãã¦ãTA ã¯ãã¡ã¤ã«ãåå¾ããããã«ã©ã®ãããªã¹ã¯ãªããè¨èªã使ç¨ããã¨èãããã¾ãã?
Task 2ã®æåã®éä¿¡ã®çãã°ãè¦ã¦ã¿ããã
{'eventVersion': '1.09', 'userIdentity': {'type': 'AWSAccount', 'principalId': '', 'accountId': 'anonymous'}, 'eventTime': '2023-11-29T08:24:07Z', 'eventSource': 's3.amazonaws.com', 'eventName': 'GetObject', 'awsRegion': 'eu-west-3', 'sourceIPAddress': '191.101.31.57', 'userAgent': '[python-requests/2.25.1]', 'requestParameters': {'bucketName': 'papa-noel', 'Host': 'papa-noel.s3.eu-west-3.amazonaws.com', 'key': 'NPoleScripts/.git/COMMIT_EDITMSG'}, 'responseElements': None, 'additionalEventData': {'aclRequired': 'Yes', 'CipherSuite': 'ECDHE-RSA-AES128-GCM-SHA256', 'bytesTransferredIn': 0, 'x-amz-id-2': 'EsErRevx2JN0jURB8pmZvZjvJyuO/JbQ+BowMNaus+9jaxwOH3jzC47Js5RRvdaNAbEn0G9Gqws=', 'bytesTransferredOut': 397}, 'requestID': 'CJECCNWQM7CK7DMX', 'eventID': '8510333e-e806-4548-bb4a-a5458d2a6743', 'readOnly': True, 'resources': [{'type': 'AWS::S3::Object', 'ARN': 'arn:aws:s3:::papa-noel/NPoleScripts/.git/COMMIT_EDITMSG'}, {'accountId': '949622803460', 'type': 'AWS::S3::Bucket', 'ARN': 'arn:aws:s3:::papa-noel'}], 'eventType': 'AwsApiCall', 'managementEvent': False, 'recipientAccountId': '949622803460', 'sharedEventID': 'da15e9f6-0264-4ba6-88f6-2030701bcb3c', 'eventCategory': 'Data', 'tlsDetails': {'tlsVersion': 'TLSv1.2', 'cipherSuite': 'ECDHE-RSA-AES128-GCM-SHA256', 'clientProvidedHostHeader': 'papa-noel.s3.eu-west-3.amazonaws.com'}}
User-Agentã«python-requests/2.25.1
ã使ããã¦ããã®ã§pythonã§ãã¦ã³ãã¼ãããããã¨ãåãããpython
ãæ£çã
Task 5
Which file did the Threat Actor locate some hard coded credentials within?
è å¨ã¢ã¯ã¿ã¼ã¯ã©ã®ãã¡ã¤ã«å ã§ãã¼ãã³ã¼ããããèªè¨¼æ å ±ãè¦ã¤ãã¾ããã?
ãã£ã¬ã¯ããªãªã¹ãã£ã³ã°ããã¦ããS3ãããã¡ã¤ã«ãå
¨é¨ãã¦ã³ãã¼ããã¦ããã
.gitãã©ã«ããåæ§ç¯ã§ããã®ã§ãgit log -p
ã§ãã°ãè¦ã¦ã¿ããã
commit a92e975c8c52221d5c1c371d5595f65eb13f8be5 (HEAD -> master) Author: Author Name <[email protected]> Date: Tue Nov 28 09:42:16 2023 +0000 Removed the sparkly creds from the script! How silly of me! Sometimes I'm about as useful as a screen saver on Santa's Sleigh!!!!!! diff --git a/claus.py b/claus.py index 6ee67e3..38938fa 100644 --- a/claus.py +++ b/claus.py @@ -5,9 +5,7 @@ import csv import boto3 from botocore.exceptions import NoCredentialsError, ClientError -# AWS Credentials - Should probably come up with a safer way to store these elf lolz! -AWS_ACCESS_KEY = 'â â â â â â â â â â â â â â â â â ' -AWS_SECRET_KEY = 'â â â â â â â â â â â â â â â â â â â â â â â â â â â â â ' +# Removed keys for safer method BUCKET_NAME = 'north-pole-private' REGION_NAME = 'eu-west-2'
èªè¨¼æ
å ±ãæ¶ããã¦ãããããã§ãããclaus.py
Task 6
Please detail all confirmed malicious IP addresses. (Ascending Order)
確èªããããã¹ã¦ã®æªæã®ãã IP ã¢ãã¬ã¹ã®è©³ç´°ãè¨è¼ãã¦ãã ããã ï¼æé ï¼
ã¨ããããIPã¢ãã¬ã¹ãåæãã¦ã¿ã¦ãã©ãããã¢ã¯ã»ã¹ããããè¦ã¦ã¿ããã
109.205.185.126 golangããarn:aws:s3:::papa-noelã«å¯¾ãã¦ã¤ãã³ãã1ã¤ã ãæ®ã£ã¦ãããæå³ä¸æ 138.199.59.46 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ 191.101.31.26 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ 191.101.31.57 arn:aws:s3:::papa-noelã«å¯¾ãã¦ãã£ã¬ã¯ããªãªã¹ãã£ã³ã°ã¨ããã¡ã¤ã«åå¾ããã¦ãããæªæ§æã 195.181.170.226 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ 3.236.115.9 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ(slackã«ãªã³ã¯ãå¼µã£ãï¼) 3.236.226.247 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ(slackã«ãªã³ã¯ãå¼µã£ãï¼) 45.133.193.41 arn:aws:s3:::north-pole-privateã«å¯¾ãã¦ã¢ã¯ã»ã¹ããããTask 7以éã®è¨åããæªæ§æãã¨åãã 45.148.104.164 arn:aws:s3:::papa-noelã«å¯¾ãã¦ä½ããã¦ãããæå³ä¸æ 86.5.206.121 大éã«ãã°ãæ®ã£ã¦ãããã2023-11-28以åã®æä½ã§ããããã°ã®éãããã¦ãææè ã®IPã¢ãã¬ã¹ã¨æ¨å¯ã§ãã
ã¨ãããã¨ã§45.133.193.41, 191.101.31.57
ãçãã
Task 7
We are extremely concerned the TA managed to compromise our private S3 bucket, which contains an important VPN file. Please confirm the name of this VPN file and the time it was retrieved by the TA.
ç§ãã¡ã¯ãTA ãéè¦ãª VPN ãã¡ã¤ã«ãå«ãç§ãã¡ã®ãã©ã¤ãã¼ã S3 ãã±ããã侵害ãããã¨ãé常ã«æ¸å¿µãã¦ãã¾ãããã® VPN ãã¡ã¤ã«ã®ååã¨ãTA ã«ãã£ã¦åå¾ãããæå»ã確èªãã¦ãã ããã
eventSource == "s3.amazonaws.com" and eventName == "GetObject"
ã®æ¡ä»¶ã§ãã°ãæ¼ãã¨bytesparkle.ovpn
ã¨ããã®ãè¦ã¤ããã
{'eventVersion': '1.09', 'userIdentity': {'type': 'IAMUser', 'principalId': 'AIDA52GPOBQCODESVPGAQ', 'arn': 'arn:aws:iam::949622803460:user/elfadmin', 'accountId': '949622803460', 'accessKeyId': 'AKIA52GPOBQCBTZ6NJXM', 'userName': 'elfadmin'}, 'eventTime': '2023-11-29T10:16:53Z', 'eventSource': 's3.amazonaws.com', 'eventName': 'GetObject', 'awsRegion': 'eu-west-2', 'sourceIPAddress': '45.133.193.41', 'userAgent': '[aws-cli/2.12.0 Python/3.11.5 Linux/6.1.0-kali9-amd64 source/x86_64.kali.2023 prompt/off command/s3.sync]', 'requestParameters': {'bucketName': 'north-pole-private', 'Host': 'north-pole-private.s3.eu-west-2.amazonaws.com', 'key': 'bytesparkle.ovpn'}, 'responseElements': None, 'additionalEventData': {'SignatureVersion': 'SigV4', 'CipherSuite': 'ECDHE-RSA-AES128-GCM-SHA256', 'bytesTransferredIn': 0, 'AuthenticationMethod': 'AuthHeader', 'x-amz-id-2': 'bW43GrgXgIHi7X277fPbnOt7T/eahMosjOIYUlJISlJyNMOUR8WJKQJX3rzps55aZ3sdek7gNX4=', 'bytesTransferredOut': 273}, 'requestID': 'DGARSWVSE9EAKMA7', 'eventID': '34e39afe-659e-438f-831c-ea354a4c19ea', 'readOnly': True, 'resources': [{'type': 'AWS::S3::Object', 'ARN': 'arn:aws:s3:::north-pole-private/bytesparkle.ovpn'}, {'accountId': '949622803460', 'type': 'AWS::S3::Bucket', 'ARN': 'arn:aws:s3:::north-pole-private'}], 'eventType': 'AwsApiCall', 'managementEvent': False, 'recipientAccountId': '949622803460', 'eventCategory': 'Data', 'tlsDetails': {'tlsVersion': 'TLSv1.2', 'cipherSuite': 'ECDHE-RSA-AES128-GCM-SHA256', 'clientProvidedHostHeader': 'north-pole-private.s3.eu-west-2.amazonaws.com'}}
bytesparkle.ovpn, 2023-11-29 10:16:53
ãæ£è§£ã
Task 8
Please confirm the username of the compromised AWS account?
侵害ããã AWS ã¢ã«ã¦ã³ãã®ã¦ã¼ã¶ã¼åã確èªãã¦ãã ãã?
Task 7ã§ä½¿ãããã¦ã¼ã¶ã¼åãçããã
elfadmin
Task 9
Based on the analysis completed Santa Claus has asked for some advice. What is the ARN of the S3 Bucket that requires locking down?
å®äºããåæã«åºã¥ãã¦ããµã³ã¿ã¯ãã¼ã¹ã¯ããã¤ãã®ã¢ããã¤ã¹ãæ±ãã¾ãããããã¯ãã¦ã³ãå¿ è¦ãª S3 ãã±ããã® ARN ã¯ä½ã§ãã?
ãã£ã¬ã¯ããªãªã¹ãã£ã³ã°ããã¦ããS3ãã±ããã®ARNãçããã¨æ£çã
arn:aws:s3:::papa-noel