Хабр Курсы для всех
РЕКЛАМА
Практикум, Хекслет, SkyPro, авторские курсы — собрали всех и попросили скидки. Осталось выбрать!
Saturday January 03, 2015 @12:09AM
«When I woke up the next morning, I had four emails from Amazon AWS and a missed phone call from Amazon AWS. Something about 140 servers running on my AWS account. What? How? I only had S3 keys on my GitHub and they where gone within 5 minutes! Turns out through the S3 API you can actually spin up EC2 instances, and my key had been spotted by a bot that continually searches GitHub for API keys. Amazon AWS customer support informed me this happens a lot recently; hackers have created an algorithm that searches GitHub 24 hours per day for API keys. Once it finds one it spins up max instances of EC2 servers to farm itself bitcoins.»
но не уверен что через ключ от s3 можно управлять ec2 инстансами…

Please do not worry about the charges at this point.
Before we can submit the refund request you will need to terminate all the instances in the various regions and then cancel the spot requests
…
I will continue to monitor your account to insure the instances have been terminated the spot requests cancelled.
Once the instances and the spot requests are deleted we will need to wait 24 hours for the billing to stabilise before we submit the refund request.

Как я умудрился за 1 день задолжать Amazon 12000$