When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.More info
- Kik Hack Tools
- Hacker Tools For Ios
- Black Hat Hacker Tools
- Tools Used For Hacking
- Hacking Tools 2020
- Hack Tools Mac
- Pentest Tools Kali Linux
- Pentest Tools For Windows
- Top Pentest Tools
- Hacker Tools
- Hacking Tools Pc
- Best Hacking Tools 2020
- Pentest Tools Tcp Port Scanner
- Hacking Tools Hardware
- Pentest Tools Bluekeep
- Hacking Tools For Beginners
- Top Pentest Tools
- Hacker Tools Linux
- Hacker Search Tools
- Pentest Tools Open Source
- Pentest Box Tools Download
- Pentest Tools Android
- Hack Tools For Ubuntu
- Pentest Recon Tools
- How To Install Pentest Tools In Ubuntu
- Hacking Tools For Windows
- Pentest Tools Windows
- Hacker Tools
- Pentest Tools Url Fuzzer
- Tools Used For Hacking
- Hacking Tools Free Download
- Usb Pentest Tools
- Pentest Tools Github
- Hacking Tools Mac
- Hacker Tools For Windows
- Hack Tools Mac
- Ethical Hacker Tools
- Hacking Tools And Software
- Hack Tools Download
- Hacker Techniques Tools And Incident Handling
- Pentest Tools Open Source
- Pentest Tools Free
- Hacking Tools Windows
- Hacking Tools For Windows
- Tools 4 Hack
- Hacker Tools Windows
- Hack Tools 2019
- Hack And Tools
- Hacking Tools And Software
- Hacking Tools Github
- Nsa Hack Tools Download
- Hacker Hardware Tools
- What Are Hacking Tools
- Hacking Tools
- Hacking Tools For Kali Linux
- How To Install Pentest Tools In Ubuntu
- Hacking App
- Github Hacking Tools
- Pentest Tools Android
- Free Pentest Tools For Windows
- Hacking Tools Free Download
- Hacker Tools Hardware
- Hacking Tools And Software
- Best Hacking Tools 2019
- Hacking Tools Download
- What Is Hacking Tools
- Game Hacking
- Pentest Box Tools Download
- Pentest Tools Tcp Port Scanner
- Pentest Tools Url Fuzzer
- Hack Tools Github
- Pentest Tools Website
- Pentest Tools Download
- Hacking Tools Software
- Hacking Tools Online
- Hack Tools Github
- Github Hacking Tools
- Hack Tools Pc
- What Are Hacking Tools
- Hacking Tools Pc
- Hack Tools For Windows
- Usb Pentest Tools
- Hacking Tools For Mac
- Termux Hacking Tools 2019
- Hacking Tools For Windows Free Download
- Hack Apps
- Pentest Tools Linux
- Wifi Hacker Tools For Windows
- Hack And Tools
- Underground Hacker Sites
- Hacking Tools For Beginners
- Hacking Tools For Windows
- Hacking Tools 2020
- Best Hacking Tools 2019
- Hacker Tools Windows
- Pentest Tools For Ubuntu
- Pentest Tools Find Subdomains
- Hack Tools Pc
- Hackrf Tools
- Hack Tools Online
- Pentest Tools Framework
- Hacker Tools
- Hack Tools Online
- Hacker Tools List
- Hacker Tools For Windows
- Hacking Tools Kit
- Hacks And Tools
- Pentest Tools Download
- Hacker Tools Free Download
- Kik Hack Tools
- Top Pentest Tools
- New Hacker Tools
- Nsa Hacker Tools
- Pentest Tools Review
- Kik Hack Tools
- Pentest Box Tools Download
- Hacking Tools For Windows 7
- Hacking Tools 2020
- Pentest Tools Open Source
- Hacker Tools Online
- Hacking Apps
- Pentest Tools Linux
- Tools Used For Hacking
- Game Hacking
- Hacker Search Tools
- Nsa Hack Tools Download
- Android Hack Tools Github
- Hacking Tools Kit
No comments:
Post a Comment