When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.- Hack Tools
- Hack Tools For Pc
- Hack Website Online Tool
- Hacker Tools For Mac
- Hacker Tools For Windows
- Hacker Tools Windows
- Hackers Toolbox
- Pentest Automation Tools
- Hacking Tools Kit
- Hacker Tools Github
- Hacking Tools Windows
- Pentest Tools Linux
- Pentest Tools Windows
- Hack Tools
- Pentest Tools Website Vulnerability
- Hacking Tools Kit
- Hackrf Tools
- Beginner Hacker Tools
- Hacker Tools 2019
- New Hack Tools
- Pentest Tools Review
- Pentest Tools Framework
- Pentest Tools Github
- Pentest Tools Free
- Hackers Toolbox
- Hacker Tools Apk
- Hacking Tools Pc
- Hacker Security Tools
- Tools For Hacker
- Hacking Tools Hardware
- Pentest Tools Port Scanner
- Hacker Tools For Pc
- Hacker Tools 2019
- Hacking App
- Hacking Tools For Windows
- Hack Tool Apk
- Pentest Tools Website Vulnerability
- Pentest Reporting Tools
- Hacking Tools Free Download
- Pentest Tools For Android
- Best Pentesting Tools 2018
- Hacker Tools Github
- Hack Apps
- Hackers Toolbox
- Hack Tools For Games
- Hackrf Tools
- Wifi Hacker Tools For Windows
- Hacking Tools For Beginners
- Pentest Recon Tools
- Hacking Tools Hardware
- Pentest Tools Windows
- Pentest Automation Tools
- Hack Tools For Games
- How To Install Pentest Tools In Ubuntu
- What Are Hacking Tools
- Top Pentest Tools
- Pentest Box Tools Download
- Best Hacking Tools 2019
- Pentest Tools Apk
- Hacker Tools Software
- What Are Hacking Tools
- New Hacker Tools
- Pentest Recon Tools
- Best Hacking Tools 2019
- Hack Apps
- Pentest Tools Android
- Pentest Tools Subdomain
- Hacking Tools Hardware
- Hacking Tools And Software
- Pentest Tools For Android
- Hacking Tools Online
- Termux Hacking Tools 2019
- Hacker Tools 2020
- Hack And Tools
- Tools Used For Hacking
- Hacker Security Tools
- Hacking Tools Hardware
- Hack Tools Github
- Hacking Tools For Windows 7
- Hacking Tools Mac
- Hacking Tools Hardware
- Hacker Tool Kit
No comments:
Post a Comment