GRUPO 40121

goGetBucket - A Penetration Testing Tool To Enumerate And Analyse Amazon S3 Buckets Owned By A Domain


When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.

What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.

The following information about every bucket found to exist will be returned:
  • List Permission
  • Write Permission
  • Region the Bucket exists in
  • If the bucket has all access disabled

Installation
go get -u github.com/glen-mac/goGetBucket

Usage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>
Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)
Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:
www.domain.com
mail.domain.com
dev.domain.com
The test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?
The keyword list (-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).
Be sure not to increase the threads too high (-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.

Related links
  1. Free Pentest Tools For Windows
  2. Game Hacking
  3. Tools Used For Hacking
  4. What Is Hacking Tools
  5. Android Hack Tools Github
  6. Hack Tools For Pc
  7. Growth Hacker Tools
  8. Hack Tool Apk
  9. Computer Hacker
  10. Hacker Tools Linux
  11. What Is Hacking Tools
  12. Nsa Hacker Tools
  13. Best Pentesting Tools 2018
  14. Hacking Tools Mac
  15. Hacking Tools For Kali Linux
  16. Hacking Tools For Mac
  17. Hack Tools Mac
  18. Hacking App
  19. Pentest Automation Tools
  20. Hacking Tools For Games
  21. Hacker Tools Software
  22. Hacker Tools Free
  23. Hack Tool Apk
  24. Physical Pentest Tools
  25. Computer Hacker
  26. Hacking Tools For Kali Linux
  27. Hackers Toolbox
  28. Tools Used For Hacking
  29. Game Hacking
  30. Hack Tools 2019
  31. Hack Website Online Tool
  32. Beginner Hacker Tools
  33. Best Hacking Tools 2019
  34. Physical Pentest Tools
  35. New Hack Tools
  36. Top Pentest Tools
  37. Hack Tools For Pc
  38. How To Hack
  39. Wifi Hacker Tools For Windows
  40. Pentest Tools Free
  41. Hacker Tools Github
  42. Hacking Tools 2019
  43. Hacker Tool Kit
  44. Hacks And Tools
  45. Best Hacking Tools 2019
  46. Hacker Tools For Mac
  47. Hack Tools For Games
  48. Pentest Tools Open Source
  49. Hacking Tools Github
  50. Hacker
  51. Hacker Tools For Windows
  52. Hacking Tools Kit
  53. Hacker Tools 2020
  54. Android Hack Tools Github
  55. Hacking Tools For Windows 7
  56. Hack Tools 2019
  57. Hacking Tools For Games
  58. Hacker Tools Free
  59. Pentest Tools Website
  60. Hacking Tools Mac
  61. Pentest Tools Online
  62. Android Hack Tools Github
  63. Pentest Tools Website
  64. Pentest Tools Open Source
  65. What Are Hacking Tools
  66. Hack Tools Github
  67. Hacking Tools Software
  68. Best Hacking Tools 2020
  69. Black Hat Hacker Tools
  70. Pentest Tools Bluekeep
  71. Hack Tools Github
  72. Hacker Tools 2020
  73. Hacker Techniques Tools And Incident Handling
  74. Easy Hack Tools
  75. Hacking Tools Name
  76. Github Hacking Tools
  77. Termux Hacking Tools 2019
  78. Hack Tool Apk
  79. Pentest Tools Alternative
  80. Hacking Tools For Games
  81. How To Install Pentest Tools In Ubuntu
  82. Hack Rom Tools
  83. What Are Hacking Tools
  84. New Hack Tools

No hay comentarios:

Publicar un comentario

Nota: solo los miembros de este blog pueden publicar comentarios.