When setting a permission policy on a resource in Amazon Web Services, it may be necessary to allow a service to perform actions on your behalf. We look into the dangers of allowing this with no additional restrictions in place, we demonstrate two styles of attack, and finally discuss defensive measures to avoid these pitfalls.