When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Related word
- Hack Tools For Mac
- Pentest Tools Nmap
- Pentest Tools Free
- Hacker Tools Free
- Hacker Tools Apk Download
- Hack Apps
- Hack Tools For Ubuntu
- Pentest Tools Android
- Hacker
- Hack App
- How To Install Pentest Tools In Ubuntu
- Hackrf Tools
- Physical Pentest Tools
- Hack Tools Pc
- Hacking Tools For Games
- Hack Tools For Windows
- Ethical Hacker Tools
- Top Pentest Tools
- Hacker Tools Apk
- Hacks And Tools
- Nsa Hack Tools Download
- Pentest Tools List
- Pentest Box Tools Download
- Nsa Hack Tools Download
- Hacker Tool Kit
- Pentest Tools Android
- Hack Tool Apk No Root
- Beginner Hacker Tools
- Hacking Tools
- Hacking Tools For Games
- Hacker Tools Online
- Hacker Tools For Pc
- Github Hacking Tools
- How To Hack
- Pentest Tools
- Hacker Hardware Tools
- Pentest Tools Review
- Hacking Apps
- Pentest Tools Apk
- Hacks And Tools
- What Is Hacking Tools
- What Are Hacking Tools
- Pentest Automation Tools
- Hackrf Tools
- Pentest Tools Subdomain
- Pentest Tools Apk
- Pentest Tools For Windows
- Physical Pentest Tools
- Pentest Tools Review
- Pentest Tools Website
- Pentest Tools Kali Linux
- Hacking Tools Hardware
- Github Hacking Tools
- Hacking Tools Free Download
- Top Pentest Tools
- Best Hacking Tools 2020
- Hacker Tools For Pc
- Hack Tools For Mac
- Hacking Tools Online
- Hacking Tools Windows 10
- Nsa Hack Tools
- Hacking Tools Pc
- Free Pentest Tools For Windows
- Github Hacking Tools
- Beginner Hacker Tools
- Pentest Tools Tcp Port Scanner
- Hacker Tools Free Download
- Hack Tools For Ubuntu
- Pentest Tools List
- Hacking Tools Windows
- Install Pentest Tools Ubuntu
- Pentest Tools Github
- Hacking Tools For Windows Free Download
- Android Hack Tools Github
- Hacking Tools Windows 10
- Hacker Tools Github
- Hack Apps
- Computer Hacker
- Hacker Tools Linux
- Pentest Tools For Ubuntu
- Pentest Tools Framework
- Hacking Tools Usb
- Android Hack Tools Github
- Free Pentest Tools For Windows
- Best Pentesting Tools 2018
- Hacking Tools For Windows 7
- Hacking Tools 2020
- Hack App
- Hacker Search Tools
- Hack Tools Pc
- Hack Tool Apk
- Hackers Toolbox
- Hackers Toolbox
- Hack Tools Mac
- Hack Tools Download
- Pentest Tools Review
- Android Hack Tools Github
- Growth Hacker Tools
- Hackers Toolbox
- Hacking App
- Hacker Tools For Windows
- Bluetooth Hacking Tools Kali
- How To Make Hacking Tools
- Hacker Hardware Tools
- Hacker Tool Kit
- Hacker Tools Software
- Pentest Tools Nmap
- Hack Tools Mac
- Hacker Tools Free Download
- Hacker Hardware Tools
- Hack Tools 2019
- Hacking App
- Pentest Tools Windows
- Hacking Tools Pc
- Hackrf Tools
- Pentest Tools Url Fuzzer
- Hacking Tools Online
- Hack Tools
- Pentest Tools Bluekeep
- Growth Hacker Tools
- Pentest Tools
- Hack Tools For Games
- Pentest Tools Website
- Hacking Tools And Software
- Hacker Tools Free
- Pentest Tools Website Vulnerability
- Hacker Tools 2020
- Pentest Tools Kali Linux
- Hack Tools For Mac
- Pentest Tools Online
- Pentest Tools Url Fuzzer
- How To Hack
- Hacker Tools Free
- World No 1 Hacker Software
0 comments:
Post a Comment