When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.Read more
- Pentest Tools Online
- Hackers Toolbox
- Hacker Techniques Tools And Incident Handling
- Hack Tool Apk
- Hack Tools For Games
- Pentest Automation Tools
- Underground Hacker Sites
- Nsa Hack Tools
- Hacker Tools Linux
- Hacking Tools Windows
- Pentest Tools For Ubuntu
- Pentest Box Tools Download
- Pentest Tools Online
- Hacker Tools Hardware
- What Is Hacking Tools
- Pentest Recon Tools
- Hacking Tools Software
- Blackhat Hacker Tools
- Hacking Tools Download
- Hacker Tools For Mac
- Pentest Tools For Mac
- Hacking Tools Pc
- Pentest Tools Nmap
- Hack Tools Pc
- New Hack Tools
- Hacker Tools For Ios
- Hacker Tools Hardware
- Hacking Tools For Games
- Hacker Tools Apk
- Hack Tools
- Pentest Tools Framework
- Bluetooth Hacking Tools Kali
- Hack And Tools
- Pentest Tools For Windows
- Blackhat Hacker Tools
- Pentest Tools Online
- Hack Apps
- Hacking Tools Hardware
- Hacker Tools Hardware
- Hacking Tools For Windows Free Download
- Hacker Security Tools
- Hacking Tools Free Download
- Growth Hacker Tools
- Beginner Hacker Tools
- Hack Tools Pc
- Pentest Tools Free
- Pentest Tools Nmap
- Hackrf Tools
- Hacking Tools Usb
- What Are Hacking Tools
- Android Hack Tools Github
- Hacking Tools And Software
- Hack Tools Download
- Hacker Tools For Ios
- Hacking Tools Kit
- Hack Website Online Tool
- Hacking Tools For Pc
- Pentest Tools Github
- Hacker Tools For Windows
- Pentest Tools For Ubuntu
- Best Hacking Tools 2019
- Hacker Hardware Tools
- Computer Hacker
- Hacker Tools Software
- Pentest Tools Review
- Hacking Tools Hardware
- Hacker Tools Free Download
- Hacker Tools Free
- Hack Tools For Ubuntu
- Hacker Tools Apk
- Hacking Tools And Software
- Hack Tools 2019
- Hacking Tools 2020
- Android Hack Tools Github
- Hacker Tools Apk
- Hacker Tools Apk
- Hack And Tools
- Hacking Tools For Games
- Free Pentest Tools For Windows
- Hacking Tools Windows
- Hacking Apps
- Hacking Tools Windows 10
- Hack Tools Download
- What Is Hacking Tools
- Pentest Tools Windows
- Bluetooth Hacking Tools Kali
- Hacker Security Tools
- Hacking Tools
- Hack Tools
- Bluetooth Hacking Tools Kali
- Hacker Tools For Windows
- Pentest Tools Github
- Nsa Hack Tools
- Hacking Tools For Pc
- Hackers Toolbox
- Pentest Tools Apk
- Hacker Tools Online
- Hack Tools Download
- Hack Tools For Ubuntu
- Hacker Tools Windows
- Best Hacking Tools 2019
- Hacking Tools Usb
- World No 1 Hacker Software
- Hacking Tools Pc
- Best Hacking Tools 2020
- Pentest Tools Download
- Hacking Tools Github
- Hacking Tools 2020
- Hacker Search Tools
- Hacks And Tools
- Pentest Tools List
- Hacker Tools 2020
- Hacker Tool Kit
- Pentest Tools Github
- Ethical Hacker Tools
- Hacking Tools Github
- Hacker Tools Github
- Hacking Tools
- Hacking Tools Github
- Hacker Hardware Tools
- How To Hack
- Hackers Toolbox
- Pentest Recon Tools
- Hack Tools Mac
- Hack Tools For Ubuntu
- Usb Pentest Tools
- Hack Tools Pc
- How To Make Hacking Tools
- Wifi Hacker Tools For Windows
- Tools Used For Hacking
- Hacking Tools Windows 10
- Hacking Tools Pc
- Hacker Tools Apk Download
- Hacker Tools Hardware
- Hack Tools
- Hack Tools For Mac
- Computer Hacker
- Pentest Reporting Tools
- Computer Hacker
- Hack And Tools
- Hacker Tools Software
- Tools For Hacker
- Pentest Tools Android
- Hackers Toolbox
- Hack Tools
- Hacking Tools For Windows Free Download
- Hacker Tools Free Download
- Computer Hacker
- Blackhat Hacker Tools
- Hacker Tools For Pc
- Hacker Tools 2019
- Best Hacking Tools 2020
- Hacking Tools Download
- Game Hacking
- Hack Tool Apk
- Hacker Tools Free Download
- Pentest Tools Port Scanner
- Hacks And Tools
- Wifi Hacker Tools For Windows
- Hacker Tools For Windows
- Hacking Tools Github
- Android Hack Tools Github
- Pentest Tools Alternative
- Hacker Tools For Windows
- Github Hacking Tools
- Pentest Tools Windows
- Tools 4 Hack
- Hacker Techniques Tools And Incident Handling
- Nsa Hack Tools
- Pentest Tools Free
No comments:
Post a Comment