When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.More information
- Android Hack Tools Github
- Hacking Tools For Kali Linux
- Hacker Tools Apk Download
- Pentest Reporting Tools
- Hacker Tools Free Download
- Pentest Tools For Ubuntu
- Tools For Hacker
- Best Hacking Tools 2020
- Hack Tools
- Pentest Tools Website
- Hacking Apps
- Hacker Search Tools
- Pentest Tools Open Source
- Hacking Tools Windows
- Hacking Tools Name
- Hack Tools
- Hacking Tools For Kali Linux
- Github Hacking Tools
- Hacking Tools Github
- Hacker Tools Free
- Hack Tools For Games
- Hack Tool Apk No Root
- Hacker Tools Online
- Hacking Tools Pc
- Pentest Tools Port Scanner
- Pentest Tools Online
- Nsa Hack Tools
- Hacker Tools Github
- Tools 4 Hack
- Hacker Techniques Tools And Incident Handling
- Tools 4 Hack
- Tools For Hacker
- Hacking Tools Github
- Hak5 Tools
- Hacker Tools Apk Download
- Hacker Tools Linux
- Hacking Tools For Windows
- Hack Website Online Tool
- Hack Tools For Ubuntu
- Hacking Tools Github
- Hack Apps
- Hacker Tools List
- Hack Tool Apk No Root
- Hacking Tools 2019
- Nsa Hack Tools
- Tools For Hacker
- Hack Tools Online
- Hacker Tools Mac
- Growth Hacker Tools
- Black Hat Hacker Tools
- New Hack Tools
- Hack Tool Apk No Root
- Hack And Tools
- Physical Pentest Tools
- Nsa Hacker Tools
- Termux Hacking Tools 2019
- Tools 4 Hack
- Pentest Tools Nmap
- Pentest Tools Online
- Blackhat Hacker Tools
- Pentest Tools Nmap
- Hack Tools For Pc
- Pentest Tools Website Vulnerability
- Hack Tools 2019
- Hacker Tool Kit
- Hacker Tools For Mac
- Pentest Automation Tools
- Hacking Tools Online
- Hacker Tools Online
- Hacking Tools For Games
- Bluetooth Hacking Tools Kali
- Pentest Tools Open Source
- Pentest Tools List
- Hacker
- Pentest Tools Review
- Pentest Tools Linux
- Pentest Tools Url Fuzzer
- Hacker Tools Free
- Hacking Tools Github
- Hacking Tools Download
- Hacking Tools For Windows 7
- Hacking Tools Github
- Pentest Tools Online
- Hacker Tools Windows
- Hacking Tools For Mac
- Hacking Tools 2020
- Hacker Tool Kit
- Hacking Tools Github
- Hacking Tools Download
- Termux Hacking Tools 2019
- Pentest Tools Linux
- Hacker Tools 2019
- Hacks And Tools
- Pentest Tools For Ubuntu
- Tools 4 Hack
- Physical Pentest Tools
- Hacker Tools Free
- Hacking Tools Online
- Usb Pentest Tools
- Pentest Tools Website Vulnerability
- Pentest Tools Nmap
- Physical Pentest Tools
- Hack Tools
- Hacker Tools Linux
- Hack Tool Apk
- Nsa Hacker Tools
- Hacking Tools Online
- Hacker Tools Software
- New Hacker Tools
- Hacker Tools List
- Pentest Tools Download
- Hacking Tools
- Pentest Tools Open Source
- Pentest Tools Windows
- Hack Tools For Games
- Hacking Tools For Kali Linux
- Hack Tool Apk
- Pentest Tools For Windows
- Hacking Tools Pc
- Hacker Tools For Pc
- Pentest Tools List
- Pentest Tools Port Scanner
- Hacking Tools Download
- Hackers Toolbox
- Hacker Tools Mac
- Hacking Tools Name
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Games
- Hacking Tools For Beginners
- Pentest Tools Website
- Hacking Tools Mac
- Pentest Tools Nmap
- Hacker Tools List
No comments:
Post a Comment