When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.More articles
- Pentest Tools Github
- Nsa Hacker Tools
- Pentest Tools For Android
- Hacking Tools For Games
- Hacker Tools For Windows
- Hacking Tools 2020
- How To Install Pentest Tools In Ubuntu
- Beginner Hacker Tools
- Wifi Hacker Tools For Windows
- Hacking Tools
- Hacker Hardware Tools
- Hacker Tools For Pc
- Hacker Tools Free
- Pentest Tools Url Fuzzer
- Pentest Tools Apk
- Computer Hacker
- Pentest Tools Windows
- Hacking Tools Download
- Hacker Search Tools
- Best Hacking Tools 2019
- Hacker Tools For Pc
- Hak5 Tools
- Tools Used For Hacking
- Hacking Tools For Kali Linux
- Hacking App
- Game Hacking
- Game Hacking
- Pentest Tools For Mac
- Hacking Tools Name
- Hacker Tools For Pc
- Nsa Hack Tools Download
- Hak5 Tools
- Pentest Tools Free
- Tools Used For Hacking
- Pentest Tools Download
- Hacker Tools 2019
- Hack App
- What Are Hacking Tools
- Hacker Tools Linux
- Hacker Tools 2019
- Hacker Techniques Tools And Incident Handling
- Pentest Automation Tools
- Tools 4 Hack
- Hack Tool Apk
- Hack And Tools
- Hacker Tools Apk
- Hacking Tools For Games
- Hackers Toolbox
- Hacker Tools Software
- Hacks And Tools
- Hacker Tools Windows
- Hacker Techniques Tools And Incident Handling
- Hacking Tools Name
- Hacking Tools For Games
- Hacking Tools Kit
- Hacker Tools For Windows
- Pentest Tools List
- Hacker Tools 2020
- Pentest Tools For Ubuntu
- Pentest Box Tools Download
- Hacking App
- Hack Apps
- Hack Tools Mac
- Hacker Tools Free Download
- Hacker Search Tools
- Beginner Hacker Tools
- Hacking Tools Mac
- What Are Hacking Tools
- Pentest Tools Windows
- Hack Tools
- Pentest Tools Github
- What Are Hacking Tools
- Physical Pentest Tools
- Pentest Tools Website
- Hack Tools
- Hacker Tools Online
- Termux Hacking Tools 2019
- Hacker Tool Kit
- Hacker Search Tools
- Pentest Tools Free
- Hacker Tools 2019
- Tools Used For Hacking
- Pentest Tools Nmap
- Hacker Techniques Tools And Incident Handling
- Termux Hacking Tools 2019
- Hack Tools Pc
- Hacking Tools For Windows 7
- What Are Hacking Tools
- Tools 4 Hack
- Tools Used For Hacking
- Hacking Tools For Games
- Hack Tools Pc
- Pentest Tools Url Fuzzer
- Android Hack Tools Github
- Top Pentest Tools
- Hacking Tools Name
- Tools Used For Hacking
- Hacking Tools Windows
- Android Hack Tools Github
- Hacking Tools For Kali Linux
- Hack Tools Online
- Hacker
- Hack Tools 2019
- Hacking Tools Mac
- Nsa Hack Tools
- Hacking Tools And Software
- Hacking Apps
- Underground Hacker Sites
- Hacker Tool Kit
- Hacker Tools Github
- Pentest Tools
- Hacker Security Tools
- Github Hacking Tools
- Usb Pentest Tools
- Tools Used For Hacking
- Hacking Tools Hardware
- Pentest Tools Open Source
- Free Pentest Tools For Windows
- Hacking Tools
- Hacker Tools Apk
- Hacker Tools List
- Hacker Tools Apk Download
- Hacking Tools Pc
- Hacking Tools Windows 10
- Hacking Tools For Beginners
- Hack Rom Tools
- Hack Website Online Tool
- Pentest Recon Tools
- Blackhat Hacker Tools
- Hacking Tools Download
- Hackers Toolbox
- Pentest Tools Port Scanner
- Pentest Tools Kali Linux
- Tools Used For Hacking
- Tools Used For Hacking
No comments:
Post a Comment