When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Related links
- Android Hack Tools Github
- Hack Tools For Pc
- Hacking Tools Name
- Best Pentesting Tools 2018
- Beginner Hacker Tools
- Hacker Tools 2019
- Best Hacking Tools 2019
- How To Make Hacking Tools
- Pentest Box Tools Download
- Hacker Tools Software
- Pentest Tools Bluekeep
- Hack Tools For Mac
- Pentest Tools Windows
- Underground Hacker Sites
- Pentest Tools Download
- Hacking Tools Name
- Hacker Search Tools
- Pentest Tools Linux
- Hacking Tools And Software
- Hacker Tools Apk
- Tools Used For Hacking
- Hacker Tools Windows
- Hack Tools Pc
- How To Install Pentest Tools In Ubuntu
- Bluetooth Hacking Tools Kali
- Computer Hacker
- Hacking Tools For Windows
- Hacker Tools For Mac
- Hacking Tools Download
- Pentest Tools Find Subdomains
- Hacking Tools For Windows Free Download
- Pentest Tools Bluekeep
- Hacker
- Hack App
- Growth Hacker Tools
- Hacking Tools
- Hack Apps
- Pentest Tools Windows
- Hack Apps
- Pentest Tools Github
- Hack Tools For Ubuntu
- Hacking Tools Hardware
- Hacker Tools For Ios
- Hack Tools For Mac
- Hack Tools
- Pentest Tools Url Fuzzer
- Hacker Tools Apk
- Kik Hack Tools
- Hacker Tools
- Hacking Tools For Mac
- Game Hacking
- Hack Tool Apk No Root
- Hacker Tools Apk Download
- Hacker Tools For Windows
- Easy Hack Tools
- Hacking Tools For Games
- Hack Tools 2019
- Hacker Tools List
- Hacking Tools For Kali Linux
- Hack Tools Mac
- Hacker Security Tools
- Hacks And Tools
- How To Hack
- World No 1 Hacker Software
- Pentest Tools Subdomain
- Hacking Tools For Windows
- Hacking Tools For Windows 7
- Growth Hacker Tools
- Hack App
- Hacker Search Tools
- Hacker
- Pentest Tools Port Scanner
- Pentest Tools Android
- Pentest Tools Find Subdomains
- Pentest Tools For Ubuntu
- Hacking Tools Online
- Hacking Tools Software
- Hack Rom Tools
- Hacker Tools 2019
- Hacking Tools Online
- Tools For Hacker
- Pentest Tools For Windows
- Hack Tools For Mac
- Hacking Tools Free Download
- Hacking App
- Hack Apps
- Hackers Toolbox
- Hack Tool Apk No Root
- Hack Tool Apk No Root
- Hack Tools Pc
- Hacking Tools Pc
- Hacker Tools Hardware
- Pentest Tools Kali Linux
- Hacking Tools For Kali Linux
- Hacking Tools For Beginners
- Pentest Tools Tcp Port Scanner
- Hacking Tools Pc
- Hacker Search Tools
- Pentest Tools
- What Are Hacking Tools
- Pentest Tools Url Fuzzer
- Pentest Tools Download
- Hacker Tools List
- Android Hack Tools Github
- Nsa Hack Tools Download
- Hack Tools
- Pentest Tools Linux
- Hacking Tools 2019
- Pentest Tools Subdomain
- Hack App
- What Are Hacking Tools
- Hack Tools For Mac
- Beginner Hacker Tools
- Pentest Tools For Android
- Hack Rom Tools
- Ethical Hacker Tools
- Pentest Reporting Tools
- Pentest Tools Subdomain
- Pentest Tools Website
- Hack App
- Hack And Tools
- Nsa Hacker Tools
- Beginner Hacker Tools
- Hacking Tools For Windows
- What Are Hacking Tools
- Pentest Tools Alternative
- Hacker Tools Apk
- Usb Pentest Tools
- Hacking Tools Windows
- Hak5 Tools
- Hacker Tools Free
- Ethical Hacker Tools
- Hacker Tools Linux
- How To Make Hacking Tools
- Hacker Tools
- Hacking Tools
- Tools Used For Hacking
- Hacking Tools Hardware
- Github Hacking Tools
- Pentest Tools Open Source
- Hacking Tools For Pc
- Pentest Tools Kali Linux
Nenhum comentário:
Postar um comentário