# VULNERABLE - Hardcoded AWS credentials
import boto3
# Never do this!
AWS_ACCESS_KEY_ID = "AKIAIOSFODNN7EXAMPLE"
AWS_SECRET_ACCESS_KEY = "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"
AWS_SESSION_TOKEN = "AQoDYXdzEJr...EXAMPLETOKEN"
s3_client = boto3.client(
's3',
aws_access_key_id=AWS_ACCESS_KEY_ID,
aws_secret_access_key=AWS_SECRET_ACCESS_KEY,
aws_session_token=AWS_SESSION_TOKEN
)
# Hardcoded RDS password
rds_connection = {
"host": "mydb.123456789012.us-east-1.rds.amazonaws.com",
"password": "MyRDSPassword123!",
"user": "admin",
"database": "production"
}