DreamHost DreamObjects
DreamHost DreamObjects is a Ceph-backed, S3-compatible object store running on `objects-<region>.dream.io`. The S3 ACL model applies; misconfig patterns mirror AWS exactly.
DreamHost DreamObjects exposure data
The trend chart appears once at least 7 days of history accrue.
Aggregate figures only. See the full open-buckets data across all providers.
Common misconfiguration class
DreamObjects is often used by smaller agencies that picked it for price, not security posture. ACL hardening guidance is sparse in DreamHost docs versus AWS, leaving buckets at the install default.
Real-world impact
Public ACL enables unauthenticated list and read on all objects. Anonymous PUT is also possible when `public-read-write` is set.
Remediation
- Set bucket ACL to `private` and grant access via per-key credentials only.
- Audit current ACLs with `s3cmd info s3://bucket` or any S3-compatible CLI.
URL patterns
DreamHost DreamObjects buckets typically resolve under hostnames like:
example.objects-us-east-1.dream.ioobjects-us-east-1.dream.io/example/
Check a specific DreamHost DreamObjects URL
Paste any DreamHost DreamObjects URL into our free Open Viewer to inspect its contents directly in your browser, no signup needed.
Open the ViewerOwn a listed DreamHost DreamObjects bucket?
If a bucket you operate appears in our index and you have remediated the misconfiguration, submit a takedown request and we'll remove it from public listings within 4 hours.
Submit takedown request