When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Related news
- Pentest Automation Tools
- Hacking Tools For Pc
- Hacking Tools For Games
- Kik Hack Tools
- Hacking Tools Free Download
- Hack Tools Pc
- Hacking Tools
- Hacking Tools Download
- Hack App
- Hacker Tools Hardware
- Hacking Tools Usb
- Hak5 Tools
- Hacking Tools Free Download
- Hacker Security Tools
- Hacking Tools Hardware
- What Is Hacking Tools
- Termux Hacking Tools 2019
- Hacker Tool Kit
- Pentest Tools Nmap
- Hacking Tools Download
- Pentest Tools Apk
- Pentest Tools Online
- Hacking Tools 2019
- Hacking Tools For Windows 7
- Blackhat Hacker Tools
- Hack And Tools
- Bluetooth Hacking Tools Kali
- Hack Tool Apk
- Hacker Hardware Tools
- Hacker Tools For Windows
- How To Install Pentest Tools In Ubuntu
- Hacker Tools Software
- Best Hacking Tools 2019
- Hacking Tools Windows 10
- Pentest Tools For Ubuntu
- Termux Hacking Tools 2019
- Pentest Tools Subdomain
- Hacker Techniques Tools And Incident Handling
- Hack Tools For Games
- What Is Hacking Tools
- Pentest Tools For Ubuntu
- New Hacker Tools
- Bluetooth Hacking Tools Kali
- What Is Hacking Tools
- Pentest Tools Free
- Nsa Hack Tools Download
- Bluetooth Hacking Tools Kali
- Pentest Recon Tools
- Pentest Tools Download
- Hacking Apps
- Hacker Tools For Pc
- Beginner Hacker Tools
- Hacking Tools
- How To Make Hacking Tools
- Hacker Tools List
- Hack Tools For Windows
- Hack Website Online Tool
- Hacking Tools For Windows
- Hacking Tools Github
- Hack Website Online Tool
- Hacker Tools Github
- Pentest Tools List
- Hack Tools 2019
- Nsa Hack Tools Download
- Underground Hacker Sites
- Hacker Tools Hardware
- Beginner Hacker Tools
- Hackers Toolbox
- Pentest Tools Website Vulnerability
No comments:
Post a Comment