When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.- Black Hat Hacker Tools
- Pentest Tools Tcp Port Scanner
- Hacker Tools Mac
- Pentest Tools List
- Pentest Tools Find Subdomains
- Hacking Tools Github
- Hacking Tools For Games
- Hack Tool Apk
- Pentest Reporting Tools
- Hack Tools Pc
- Hacking Tools For Windows
- Wifi Hacker Tools For Windows
- Hacking Tools Software
- Best Hacking Tools 2020
- Hacking Tools For Windows 7
- Hack Tools Download
- Usb Pentest Tools
- Best Hacking Tools 2019
- Easy Hack Tools
- Physical Pentest Tools
- Hacker Tools For Mac
- Pentest Recon Tools
- New Hack Tools
- Hacking Tools Kit
- Pentest Tools Find Subdomains
- Hack Tools For Pc
- What Are Hacking Tools
- Hacker Techniques Tools And Incident Handling
- Hacking Tools For Beginners
- Pentest Tools Linux
- Hacking Tools Free Download
- Hack Tools For Mac
- Hacking Tools Usb
- Hacking Tools Pc
- Pentest Tools Kali Linux
- Hacking Tools For Kali Linux
- Tools For Hacker
- Hacker Tool Kit
- Hacking Tools For Games
- Pentest Tools Windows
- Hack Tools 2019
- Termux Hacking Tools 2019
- Usb Pentest Tools
- Pentest Box Tools Download
- Blackhat Hacker Tools
- Hack Tools For Windows
- Hack Tools Pc
- Hacking Tools And Software
- Hacker Tools Free Download
- Hacking Tools For Mac
- Hacking Tools Hardware
- Hacking Tools 2020
- Termux Hacking Tools 2019
- Hacking Apps
- Hacking Tools Github
- Pentest Reporting Tools
- Hacker Search Tools
- Pentest Tools Review
- Tools 4 Hack
- Hacking Tools Kit
- Hacker Tools Free Download
- Hacker Tools Mac
- Hacking Tools Kit
- Pentest Tools Find Subdomains
- Hacker Tools Software
- How To Install Pentest Tools In Ubuntu
- Easy Hack Tools
- Hack Website Online Tool
- Hacking Tools
- Hacker Tools Hardware
- Hack Tools 2019
- What Are Hacking Tools
- Hacker Hardware Tools
- Hack And Tools
- Hacker Tools Free Download
- Pentest Tools For Mac
- Hacking Tools Github
- Github Hacking Tools
- Pentest Tools Online
- Hacking Tools Name
- Pentest Tools Windows
- Hacker Tools For Pc
- Bluetooth Hacking Tools Kali
- Hack Tools
- Computer Hacker
- Hacking Tools Software
- Hack Tools For Games
- Hacking Tools Github
- Hacking Tools Github
- Hacking Tools For Windows Free Download
- Pentest Tools For Mac
- Pentest Tools Review
- Hacker Tools For Windows
- Hacking Tools For Pc
- Hackrf Tools
- Hacking Tools Name
- Black Hat Hacker Tools
- Best Pentesting Tools 2018
- Tools Used For Hacking
- Hacker Tools For Ios
- Underground Hacker Sites
- Pentest Tools Subdomain
- Hacking Apps
- How To Make Hacking Tools
- Hacking Tools Pc
- Hak5 Tools
- Install Pentest Tools Ubuntu
- Hacking Tools For Pc
- World No 1 Hacker Software
- New Hack Tools
- Hacker Tools Online
- Hack Tools For Games
- Hacking App
- Github Hacking Tools
- Hak5 Tools
- Hacker Tools Apk
- How To Make Hacking Tools
- Pentest Tools Review
- How To Make Hacking Tools
- Pentest Tools Github
- Beginner Hacker Tools
- Hacker Security Tools
- Pentest Tools Website Vulnerability
- What Are Hacking Tools
- Hacker Tools 2020
- Hack Tools Download
- Hack Tools Download
- Hacker Tools Online
- Best Hacking Tools 2020
- Hacking Tools Download
- Android Hack Tools Github
- Easy Hack Tools
- Bluetooth Hacking Tools Kali
- Hacker Tools Windows
- Hacker Techniques Tools And Incident Handling
- Pentest Tools Review
- Hack Tool Apk No Root
- What Is Hacking Tools
- Hacker Tools Free
- Pentest Tools Windows
- Hacking Tools Mac
- New Hack Tools
- Hacker Tools Free
- Pentest Tools Android
- Pentest Tools Url Fuzzer
- New Hack Tools
- Hacking Tools 2019
- Hacking Tools For Mac
- Tools 4 Hack
- Nsa Hacker Tools
- Pentest Tools Port Scanner
- Pentest Tools Linux
- Termux Hacking Tools 2019
Tiada ulasan:
Catat Ulasan