1 2 Ambtion.com 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 Ambtion.com 279 280 281 Advertise Free on Auto-pilot!
Watch the latest videos on YouTube.com
newgoldenjewels: goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain

Sunday, August 23, 2020

goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain


When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.

What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.

The following information about every bucket found to exist will be returned:
  • List Permission
  • Write Permission
  • Region the Bucket exists in
  • If the bucket has all access disabled

Installation
go get -u github.com/glen-mac/goGetBucket

Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:
www.domain.com
mail.domain.com
dev.domain.com
The test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?
The keyword list (-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).
Be sure not to increase the threads too high (-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.

More info

  1. Kik Hack Tools
  2. Hacker Tools For Ios
  3. Black Hat Hacker Tools
  4. Tools Used For Hacking
  5. Hacking Tools 2020
  6. Hack Tools Mac
  7. Pentest Tools Kali Linux
  8. Pentest Tools For Windows
  9. Top Pentest Tools
  10. Hacker Tools
  11. Hacking Tools Pc
  12. Best Hacking Tools 2020
  13. Pentest Tools Tcp Port Scanner
  14. Hacking Tools Hardware
  15. Pentest Tools Bluekeep
  16. Hacking Tools For Beginners
  17. Top Pentest Tools
  18. Hacker Tools Linux
  19. Hacker Search Tools
  20. Pentest Tools Open Source
  21. Pentest Box Tools Download
  22. Pentest Tools Android
  23. Hack Tools For Ubuntu
  24. Pentest Recon Tools
  25. How To Install Pentest Tools In Ubuntu
  26. Hacking Tools For Windows
  27. Pentest Tools Windows
  28. Hacker Tools
  29. Pentest Tools Url Fuzzer
  30. Tools Used For Hacking
  31. Hacking Tools Free Download
  32. Usb Pentest Tools
  33. Pentest Tools Github
  34. Hacking Tools Mac
  35. Hacker Tools For Windows
  36. Hack Tools Mac
  37. Ethical Hacker Tools
  38. Hacking Tools And Software
  39. Hack Tools Download
  40. Hacker Techniques Tools And Incident Handling
  41. Pentest Tools Open Source
  42. Pentest Tools Free
  43. Hacking Tools Windows
  44. Hacking Tools For Windows
  45. Tools 4 Hack
  46. Hacker Tools Windows
  47. Hack Tools 2019
  48. Hack And Tools
  49. Hacking Tools And Software
  50. Hacking Tools Github
  51. Nsa Hack Tools Download
  52. Hacker Hardware Tools
  53. What Are Hacking Tools
  54. Hacking Tools
  55. Hacking Tools For Kali Linux
  56. How To Install Pentest Tools In Ubuntu
  57. Hacking App
  58. Github Hacking Tools
  59. Pentest Tools Android
  60. Free Pentest Tools For Windows
  61. Hacking Tools Free Download
  62. Hacker Tools Hardware
  63. Hacking Tools And Software
  64. Best Hacking Tools 2019
  65. Hacking Tools Download
  66. What Is Hacking Tools
  67. Game Hacking
  68. Pentest Box Tools Download
  69. Pentest Tools Tcp Port Scanner
  70. Pentest Tools Url Fuzzer
  71. Hack Tools Github
  72. Pentest Tools Website
  73. Pentest Tools Download
  74. Hacking Tools Software
  75. Hacking Tools Online
  76. Hack Tools Github
  77. Github Hacking Tools
  78. Hack Tools Pc
  79. What Are Hacking Tools
  80. Hacking Tools Pc
  81. Hack Tools For Windows
  82. Usb Pentest Tools
  83. Hacking Tools For Mac
  84. Termux Hacking Tools 2019
  85. Hacking Tools For Windows Free Download
  86. Hack Apps
  87. Pentest Tools Linux
  88. Wifi Hacker Tools For Windows
  89. Hack And Tools
  90. Underground Hacker Sites
  91. Hacking Tools For Beginners
  92. Hacking Tools For Windows
  93. Hacking Tools 2020
  94. Best Hacking Tools 2019
  95. Hacker Tools Windows
  96. Pentest Tools For Ubuntu
  97. Pentest Tools Find Subdomains
  98. Hack Tools Pc
  99. Hackrf Tools
  100. Hack Tools Online
  101. Pentest Tools Framework
  102. Hacker Tools
  103. Hack Tools Online
  104. Hacker Tools List
  105. Hacker Tools For Windows
  106. Hacking Tools Kit
  107. Hacks And Tools
  108. Pentest Tools Download
  109. Hacker Tools Free Download
  110. Kik Hack Tools
  111. Top Pentest Tools
  112. New Hacker Tools
  113. Nsa Hacker Tools
  114. Pentest Tools Review
  115. Kik Hack Tools
  116. Pentest Box Tools Download
  117. Hacking Tools For Windows 7
  118. Hacking Tools 2020
  119. Pentest Tools Open Source
  120. Hacker Tools Online
  121. Hacking Apps
  122. Pentest Tools Linux
  123. Tools Used For Hacking
  124. Game Hacking
  125. Hacker Search Tools
  126. Nsa Hack Tools Download
  127. Android Hack Tools Github
  128. Hacking Tools Kit

No comments: