When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Continue reading
- Tools 4 Hack
- Hacking Tools For Mac
- Pentest Tools Subdomain
- Hack Tools For Games
- Hack App
- Physical Pentest Tools
- Pentest Tools Find Subdomains
- Hacking Tools Hardware
- Pentest Tools Find Subdomains
- Hacking Tools Name
- Hack Rom Tools
- Hacking Tools Github
- Hacker Techniques Tools And Incident Handling
- Tools For Hacker
- Hacker Tools Free Download
- World No 1 Hacker Software
- Hacker Search Tools
- Hack Tools For Pc
- Hacker Techniques Tools And Incident Handling
- Pentest Tools Nmap
- Termux Hacking Tools 2019
- Hack Tools
- Blackhat Hacker Tools
- Pentest Tools Nmap
- Pentest Reporting Tools
- How To Make Hacking Tools
- Nsa Hack Tools
- Hacking Tools Online
- Best Pentesting Tools 2018
- Hacker Tools Linux
- Hack Tools Mac
- Hack Tools
- Hackrf Tools
- Nsa Hacker Tools
- Pentest Tools Url Fuzzer
- Hack Tools Online
- Hack Tools 2019
- Hacker Tools 2020
- Hack Tools
- Best Pentesting Tools 2018
- Pentest Tools Framework
- Hack Tools For Games
- How To Install Pentest Tools In Ubuntu
- Blackhat Hacker Tools
- Hacking App
- Free Pentest Tools For Windows
- Hacking Tools Windows 10
- Hacker Tools 2020
- Termux Hacking Tools 2019
- Hacker Hardware Tools
- Install Pentest Tools Ubuntu
- Usb Pentest Tools
- Beginner Hacker Tools
- Pentest Box Tools Download
- Best Pentesting Tools 2018
- Pentest Tools Open Source
- Hacking Tools Windows
- Hacker Tools Hardware
- Hacker
- Hack Rom Tools
- Hackrf Tools
- Hacking Tools For Pc
- Hack Tools 2019
- Hack Tools Download
- Hacker Security Tools
- Nsa Hacker Tools
- Hacking Tools
- Android Hack Tools Github
0 comments:
Post a Comment