goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain
When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucket
Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i
) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.com
The test file (-f
) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k
) is concatenated with the root domain name (-d
) and the domain without the TLD to permutate using the supplied permuation wordlist (-m
).Be sure not to increase the threads too high (
-t
) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.- Hack Tools For Windows
- Bluetooth Hacking Tools Kali
- Pentest Tools Find Subdomains
- Pentest Tools For Mac
- Pentest Tools Tcp Port Scanner
- Pentest Tools Nmap
- Pentest Tools Download
- Pentest Tools
- Hack Tools Mac
- Hackrf Tools
- New Hacker Tools
- Hackers Toolbox
- Hacking Tools For Games
- Pentest Tools For Android
- What Is Hacking Tools
- What Is Hacking Tools
- Hacker Tools Apk
- Hacking Tools Free Download
- Hacking Tools Online
- Pentest Tools Url Fuzzer
- Pentest Tools Android
- Hacker Tools For Pc
- Free Pentest Tools For Windows
- Computer Hacker
- Hacking Tools Kit
- Pentest Reporting Tools
- Hack Website Online Tool
- Pentest Tools List
- Pentest Tools For Android
- Hacker
- Blackhat Hacker Tools
- Hacking Apps
- Hacking Tools Free Download
- What Is Hacking Tools
- Hacker Tools Software
- Hacking Tools 2019
- New Hacker Tools
- Hacking Tools Download
- Underground Hacker Sites
- Hacker Tool Kit
- Install Pentest Tools Ubuntu
- Pentest Tools For Mac
- Hack Website Online Tool
- Free Pentest Tools For Windows
- Game Hacking
- Pentest Tools Github
- Computer Hacker
- Pentest Automation Tools
- Hack Tools For Mac
- Best Pentesting Tools 2018
- Hacking Tools Pc
- Hacking Tools 2019
- Hacking Tools For Windows
- Github Hacking Tools
- Pentest Tools
- Pentest Tools Online
- Hacking Tools Mac
- Hacker Techniques Tools And Incident Handling
- Hackers Toolbox
- Computer Hacker
- Pentest Tools Kali Linux
- Hacker Hardware Tools
- Pentest Tools Bluekeep
- Bluetooth Hacking Tools Kali
- Pentest Tools For Windows
- Hacker Tools For Pc
- Hack App
- Hacking Tools For Beginners
- Hack And Tools
- Hacker Tools For Mac
- Hacker Tools Mac
- Hack Apps
- Top Pentest Tools
- Physical Pentest Tools
- Pentest Tools Nmap
- Hacking Tools
- Pentest Tools For Mac
- Hacking Tools For Games
- Hacker Tools Mac
- Hacker Tools Hardware
- Pentest Tools Open Source
- Hacker Security Tools
- Hacking Tools Download
- Hacker Tools For Windows
- Hacking Tools Free Download
- Best Hacking Tools 2020
- Hacking Tools For Windows 7
- Pentest Tools Find Subdomains
- Hacker Tools 2020
- Physical Pentest Tools
- Hacker Tool Kit
0 Comments:
Post a Comment
<< Home