When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucketUsage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.comThe test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).Be sure not to increase the threads too high (
-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.- Hacker Tools List
- Pentest Tools Windows
- Nsa Hacker Tools
- Hacker Techniques Tools And Incident Handling
- Pentest Box Tools Download
- Hacking Tools Software
- Pentest Tools Tcp Port Scanner
- Pentest Tools Download
- Hacker Hardware Tools
- Hack Tool Apk
- Underground Hacker Sites
- Pentest Tools Url Fuzzer
- Physical Pentest Tools
- Hacking Tools Free Download
- Hacker Techniques Tools And Incident Handling
- Hacker Tools Linux
- Pentest Reporting Tools
- Pentest Tools Website Vulnerability
- Hacking Tools Download
- Pentest Tools Port Scanner
- Pentest Tools For Ubuntu
- Hacking Tools For Windows 7
- Hacker Hardware Tools
- Best Pentesting Tools 2018
- Pentest Tools Bluekeep
- Pentest Tools Android
- Hack Tools Mac
- Hacker Tools Apk
- Hack Tool Apk No Root
- Hack Tools Github
- Hack Tools For Windows
- Install Pentest Tools Ubuntu
- Hackers Toolbox
- World No 1 Hacker Software
- Hacking Tools
- Pentest Tools For Android
- Hacker Hardware Tools
- Underground Hacker Sites
- Hacker Tools Free
- Hacking Tools For Kali Linux
- Hack Website Online Tool
- Hacking Tools Kit
- Blackhat Hacker Tools
- Pentest Tools Download
- Hacker Tools Apk Download
- Hack Tools For Mac
- Hack App
- Pentest Reporting Tools
- Hack Tools Download
- Pentest Reporting Tools
- Pentest Tools List
- Hacking Tools Online
- Best Hacking Tools 2019
- Hacker Tools Mac
- Hack And Tools
- Hacker Hardware Tools
- Hack Tools For Games
- Ethical Hacker Tools
- Pentest Tools Tcp Port Scanner
- Hacker Tools List
- Pentest Recon Tools
- How To Install Pentest Tools In Ubuntu
- Free Pentest Tools For Windows
- Usb Pentest Tools
- Pentest Tools Framework
- Pentest Tools Android
- Hacking Tools Windows 10
- Hacker Tools Hardware
- Hacking Tools For Kali Linux
- Hacker Tools Linux
- Hacking Tools For Windows 7
- Hacker Tools For Windows
- Hacking Tools Online
- Hacking Tools And Software
- Growth Hacker Tools
- Pentest Tools Framework
- Top Pentest Tools
- Hack Tools For Ubuntu
- Pentest Automation Tools
- Hacking Tools For Beginners
- Hacking Tools Name
- New Hacker Tools
- Hacking Tools Online
- Top Pentest Tools
- Hack Tools 2019
- Github Hacking Tools
- Hacking Tools Online
- Tools 4 Hack
- Pentest Tools For Ubuntu
- Termux Hacking Tools 2019
- Hackrf Tools
- Hacking Tools
- Hack Tools Pc
- Hacker Tools Linux
- Hacking Tools 2020
- Pentest Tools Website
- Nsa Hacker Tools
- Pentest Box Tools Download
- What Is Hacking Tools
- Hacking Tools Windows
- Pentest Tools Open Source
- Pentest Tools Url Fuzzer
- Hacking Tools 2020
- Wifi Hacker Tools For Windows
- Pentest Tools Open Source
- Hack Tool Apk No Root
- Best Hacking Tools 2019
- Hacking App
- Pentest Tools For Android
- Pentest Tools Android
- Hacking App
- Underground Hacker Sites
- Best Pentesting Tools 2018
- Pentest Recon Tools
- Hacker Tools 2019
- Hack App
- Github Hacking Tools
- Hacker Tools Online
- Hacker Tools Hardware

No comments:
Post a Comment