When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.More articles
- Hacker Tools Free Download
- Hacking Tools For Kali Linux
- Install Pentest Tools Ubuntu
- Free Pentest Tools For Windows
- Pentest Tools Github
- Pentest Tools Review
- Hacking Tools 2019
- Hack Tools
- Hacking Tools Name
- Hacking Tools 2020
- Hack Tools For Ubuntu
- Hackrf Tools
- Termux Hacking Tools 2019
- Github Hacking Tools
- Tools For Hacker
- Hack Tools Pc
- Hack Tools Download
- Hacker Search Tools
- Hacking Tools
- Easy Hack Tools
- Hack Tools For Ubuntu
- Hacking Tools Name
- Hackrf Tools
- How To Make Hacking Tools
- Hack Tools For Pc
- Hacking Tools For Beginners
- Hack App
- Pentest Tools Github
- Pentest Tools Nmap
- What Is Hacking Tools
- Hack Tools
- Blackhat Hacker Tools
- Hacker Tools For Ios
- Hacker Tools Free
- Best Hacking Tools 2019
- Hacking Tools Name
- Hacking Tools Hardware
- Usb Pentest Tools
- Hackers Toolbox
- Black Hat Hacker Tools
- New Hack Tools
- Hacker Tools For Ios
- Pentest Tools Website
- Hacker Tools Free
- Hack Tool Apk No Root
- Hack Tools Pc
- What Is Hacking Tools
- Hacking Tools Free Download
- Pentest Automation Tools
- Pentest Tools Free
- Hacker Tools For Ios
- Growth Hacker Tools
- Pentest Tools
- Hack Tools For Games
- Hacker Search Tools
- Hacking Tools Windows 10
- Hacker Tools Github
- Pentest Tools Website Vulnerability
- Hacking App
- Hack App
- Hacker Tools For Windows
- Pentest Tools Free
- Pentest Tools Website Vulnerability
- Hacking Tools Hardware
- Pentest Tools Download
- What Is Hacking Tools
- Pentest Tools Apk
- Easy Hack Tools
- Nsa Hack Tools
- Pentest Tools Alternative
- Github Hacking Tools
- Tools 4 Hack
- Hack Tools Github
- Hacker Tools Windows
- Nsa Hack Tools Download
- Free Pentest Tools For Windows
- Nsa Hacker Tools
- Hacker Tools Free
- Tools For Hacker
- Pentest Tools Bluekeep
- Hacking Tools Windows
- Hack Tools Github
- Github Hacking Tools
- Hack Tools Download
- Hacker Tools Free Download
- Hacker Tools Windows
- New Hacker Tools
- Pentest Tools Linux
- Pentest Tools Apk
- Hack App
- Hacker Tools Windows
- Hacking Tools And Software
- Hack Tools
- Hacker Tools 2019
- Hacker Tools 2020
- Pentest Tools Bluekeep
- Pentest Tools Website
- World No 1 Hacker Software
- Nsa Hack Tools
- Hacker Tools Software
- Game Hacking
- Hacking Tools For Windows
- Kik Hack Tools
- Pentest Tools Port Scanner
- New Hacker Tools
- Pentest Tools Bluekeep
- Android Hack Tools Github
- Install Pentest Tools Ubuntu
- Pentest Tools
- Hacker Tools Mac
- Hacker Tools Linux
- Pentest Tools Apk
- Best Hacking Tools 2020
- Hacking Tools Software
- Hacker Tools Apk Download
- Hacker
- Pentest Tools Website Vulnerability
- Hacking Tools Github
- Hacking Tools For Kali Linux
- World No 1 Hacker Software
- Hack Tools For Windows
- Hacking Tools And Software
- Hack Tools Github
- Pentest Tools Tcp Port Scanner
- Hacker Tools Online
- Hack Tools For Windows
- Hacking Tools For Mac
No comments:
Post a Comment