When performing a recon on a domain - understanding assets they own is very important. AWS S3 bucket permissions have been confused time and time again, and have allowed for the exposure of sensitive material.
What this tool does, is enumerate S3 bucket names using common patterns I have identified during my time bug hunting and pentesting. Permutations are supported on a root domain name using a custom wordlist. I highly recommend the one packaged within AltDNS.
The following information about every bucket found to exist will be returned:
- List Permission
- Write Permission
- Region the Bucket exists in
- If the bucket has all access disabled
Installation
go get -u github.com/glen-mac/goGetBucketUsage
goGetBucket -m ~/tools/altdns/words.txt -d <domain> -o <output> -i <wordlist>Usage of ./goGetBucket:
-d string
Supplied domain name (used with mutation flag)
-f string
Path to a testfile (default "/tmp/test.file")
-i string
Path to input wordlist to enumerate
-k string
Keyword list (used with mutation flag)
-m string
Path to mutation wordlist (requires domain flag)
-o string
Path to output file to store log
-t int
Number of concurrent threads (default 100)Throughout my use of the tool, I have produced the best results when I feed in a list (-i) of subdomains for a root domain I am interested in. E.G:www.domain.com
mail.domain.com
dev.domain.comThe test file (-f) is a file that the script will attempt to store in the bucket to test write permissions. So maybe store your contact information and a warning message if this is performed during a bounty?The keyword list (
-k) is concatenated with the root domain name (-d) and the domain without the TLD to permutate using the supplied permuation wordlist (-m).Be sure not to increase the threads too high (
-t) - as the AWS has API rate limiting that will kick in and start giving an undesired return code.- Hacker Tools Online
- Hacking Apps
- Hacker Tools Free Download
- World No 1 Hacker Software
- Hack Apps
- Hacker Hardware Tools
- Pentest Tools Online
- Hacking Tools Windows 10
- Hack Tools 2019
- Pentest Tools Url Fuzzer
- Hacker Tools Apk
- Computer Hacker
- Pentest Tools For Windows
- Hacking Tools For Windows 7
- Pentest Tools Tcp Port Scanner
- Pentest Tools Windows
- Underground Hacker Sites
- Tools 4 Hack
- Android Hack Tools Github
- Hack Tools Pc
- Hacker Tools Software
- Pentest Tools Android
- Hacking Tools For Windows
- Pentest Tools Github
- Computer Hacker
- Hacking Apps
- Hacking Tools 2020
- Hacking Tools 2020
- Github Hacking Tools
- Hack Tools For Games
- World No 1 Hacker Software
- New Hack Tools
- Hack Tools 2019
- Bluetooth Hacking Tools Kali
- Hacker Tools Linux
- Nsa Hacker Tools
- Kik Hack Tools
- Hacking Tools For Windows
- Pentest Tools Online
- Hacking Tools Usb
- Wifi Hacker Tools For Windows
- Growth Hacker Tools
- Hack Tools Pc
- Physical Pentest Tools
- Underground Hacker Sites
- What Are Hacking Tools
- Hacker Tools Github
- Pentest Tools Online
- Pentest Tools
- Hacking Tools Pc
- Pentest Automation Tools
- Hacker Tools Free
- Hack App
- Pentest Tools Android
- How To Make Hacking Tools
- Computer Hacker
- How To Make Hacking Tools
- Hack Tool Apk No Root
- Github Hacking Tools
- Hack Tools Online
- Hacker Tools Free
- Best Pentesting Tools 2018
- How To Make Hacking Tools
- Hack And Tools
- Hack Tools Online
- Game Hacking
- Game Hacking
- Pentest Tools For Windows
- Hack Tools 2019
- Pentest Tools Download
- Hack Tool Apk No Root
- Pentest Tools Framework
- Beginner Hacker Tools
- Hackers Toolbox
- Hacking Tools Windows
- Pentest Automation Tools
- Hacking Tools
- How To Hack
- Android Hack Tools Github
- Hack Tool Apk No Root
- Blackhat Hacker Tools
- Hacking Tools For Windows Free Download
- New Hacker Tools
- Hacker Tool Kit
- Hack Tools For Ubuntu
- Tools 4 Hack
- Hack Tools 2019
- How To Install Pentest Tools In Ubuntu
- Hack Tools Mac
- Bluetooth Hacking Tools Kali
- New Hacker Tools
- Hackrf Tools
- Pentest Tools Url Fuzzer
- Hack Rom Tools
- Pentest Tools Free
- World No 1 Hacker Software
- Pentest Tools Linux
- Hacker Tools Software
- Hacking Tools Online
- Pentest Tools Android
- Top Pentest Tools
- Hacking Tools For Pc
- Pentest Tools For Ubuntu
- Hacker Tools For Mac
- Pentest Tools Kali Linux
- Hack And Tools
- Blackhat Hacker Tools
- Pentest Tools Tcp Port Scanner
- World No 1 Hacker Software
- Hacking Tools Usb
- Hacking Tools For Windows
- Hacker Tools 2019
- Underground Hacker Sites
- Tools 4 Hack
- Pentest Tools Url Fuzzer
- Hack Apps
- Best Hacking Tools 2019
- Github Hacking Tools
- Hack Apps
- Hack Tools Online
- Pentest Tools Tcp Port Scanner
- Pentest Tools Download
- Best Hacking Tools 2020
- Hack Tools Online
- Hacking Tools Download
- Computer Hacker
- New Hack Tools
- Hacker Tools Hardware
- Hack Tools Github
- Hacking Tools Github
- Pentest Tools For Ubuntu
- Hacking Tools For Mac
- Hacker Tools List
- Tools Used For Hacking
- Pentest Tools Linux
- Hacker Tools For Pc
- Hacker Tools 2020
- Hacking Tools Kit
- Pentest Tools For Mac
- Tools For Hacker
- How To Hack
- Pentest Tools For Windows
- Hacking Tools 2020
- Hacker Tools For Windows
- Pentest Tools Free
- Underground Hacker Sites
- Pentest Tools Website
- What Are Hacking Tools
- Wifi Hacker Tools For Windows
- Hack Tools For Mac
- Pentest Tools Subdomain
- Hacking Tools For Windows 7
- Hacker Tools Mac
- Bluetooth Hacking Tools Kali
