S3 Bucket Enumeration & Pillage
Versionv2.1
Difficulty Intermediate
Updated2025-04-20
CategoryCloud & Infrastructure

S3 Bucket Enumeration & Pillage

$34.99

S3 Bucket Enumeration & Pillage

n

Tool for descubrir and exploit buckets S3 mal configured:

n
    n
  • Enumeration — Genera names of bucket basados in the target (company-backup, company-dev, company-logs) and verifies existsncia.
  • n
  • Permission check — For each bucket enagainstdo: ListBucket, GetObject, PutObject, GetBucketAcl, GetBucketPolicy.
  • n
  • Content analysis — Lista objetos and filters by extension sensible (.sql, .env, .pem, .key, .csv, .xlsx, .bak).
  • n
  • Selective download — Desloads only files that matchean patterns sensibles (no desloads TBs of logs).
  • n
  • Cross-account — Test access with credentials of different countss AWS si disponibles.
  • n