When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Related news
- Hacker Tools 2020
- Hacker Security Tools
- Pentest Tools Subdomain
- Hacker Tools List
- Hacker Tools
- Hacking Tools Name
- World No 1 Hacker Software
- Game Hacking
- What Is Hacking Tools
- Underground Hacker Sites
- Hacker
- Pentest Tools Bluekeep
- Pentest Tools Bluekeep
- Pentest Tools
- Top Pentest Tools
- Hacking Tools Free Download
- Pentest Automation Tools
- Usb Pentest Tools
- Pentest Tools Bluekeep
- Hacker Tools Apk
- Hacker Tools For Windows
- Pentest Tools Find Subdomains
- Termux Hacking Tools 2019
- Pentest Tools Framework
- Blackhat Hacker Tools
- Hack Tools Github
- Hacks And Tools
- How To Make Hacking Tools
- Hacking Tools Software
- Hacker Tools 2020
- Hack Tools For Games
- Hacker Techniques Tools And Incident Handling
- Pentest Tools Port Scanner
- Hacker Tools Software
- Pentest Reporting Tools
- Hacking Tools For Kali Linux
- Hacker Tools Windows
- Usb Pentest Tools
- Hack Tool Apk
- Hacking Tools Free Download
- Pentest Tools Kali Linux
- Pentest Tools Review
- Tools 4 Hack
- Hack Tools For Ubuntu
- Pentest Box Tools Download
- Hacker Tools For Pc
- Hacker Tools Software
- Nsa Hack Tools Download
- Hack Tools Github
- Pentest Tools Framework
- Hack Tools 2019
- Free Pentest Tools For Windows
- Nsa Hacker Tools
- Beginner Hacker Tools
- Hack Tools Github
- Pentest Tools Github
- New Hack Tools
- Hacking Tools Kit
- Hacker Tools Free Download
- Tools For Hacker
- Best Hacking Tools 2020
- Pentest Tools For Windows
- Pentest Automation Tools
- New Hacker Tools
- Hacker Tools Mac
- Pentest Tools Open Source
- Hacker Tools Free
- Hacking Tools For Windows
- Hacking Tools And Software
- Pentest Tools For Windows
- Hacking Tools For Windows 7
- Hacker Tools For Windows
- Pentest Tools Review
- Hacking Tools 2019
- Physical Pentest Tools
- Hack Tools Online
- Hacking Tools 2020
- What Are Hacking Tools
- Pentest Tools Online
- Hack Tools For Pc
- Beginner Hacker Tools
- Hacking Tools For Windows Free Download
- Best Pentesting Tools 2018
- Pentest Tools Free
- Hacker Tools Mac
- Hacking Tools Hardware
- Hacking Tools For Games
- Hacking Tools For Windows
- Pentest Tools Find Subdomains
- Hacker Tools Github
- Kik Hack Tools
- Black Hat Hacker Tools
- What Are Hacking Tools
- Hacker Tools Apk Download
- Hacking Tools For Mac
- Hacking Tools 2020
- Termux Hacking Tools 2019
- Hacking Tools 2020
- Pentest Tools Framework
- Pentest Tools Online
- Black Hat Hacker Tools
- World No 1 Hacker Software
- Pentest Tools Framework
- Hacker Tools Linux
- Hacking Tools And Software
- Hacker Tools For Windows
- Hak5 Tools
- Install Pentest Tools Ubuntu
- Pentest Tools Url Fuzzer
- Pentest Tools Linux
- Hacker
- Hacker Tool Kit
- Hack Tools
- Hacking Tools Pc
- Hacker Tools Free
- Hack Tools For Games
- Hacking Tools For Games
- Hacker Techniques Tools And Incident Handling
- Hack Tool Apk No Root
- Hacking Tools Windows 10
- Hack Tools 2019
- Hacker Hardware Tools
- What Are Hacking Tools
- Nsa Hack Tools
- Hacker
- Hacker Tools For Mac
- Top Pentest Tools
- Pentest Tools Find Subdomains
- Hacking App
- Hack Tools For Mac
- Hacking Tools Hardware
- Pentest Tools Subdomain
- What Are Hacking Tools
- Hacking Tools Github
- Pentest Tools Review
- Hacker Tools 2019
- New Hacker Tools
- Hacker Tools
- Hack Tools For Games
- Termux Hacking Tools 2019
- Hacking Tools For Kali Linux
- Hacker Tool Kit
- Github Hacking Tools
- Hacking Tools And Software
- Growth Hacker Tools
- Hack Apps
No comments:
Post a Comment