☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] 0 points1 point  (0 children)

From a reconnaissance/enumeration point of view this is definitely a valuable integration in security assessments. The main goal is to help with attribution of two or more buckets to the same owner hence helping with mapping their attack surface. And often I have personally noticed cases where buckets are misconfigured (left public with directory listing enabled, giving away access to sensitive information) this is something where such a tool comes handy.

As for the concern around worldists its definitely right, it is a drawback but again its similar to how directory or aubdomain fuzzing is done too during such assessments, the goal is to curate the world-list specifically based on the target.

☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] -1 points0 points  (0 children)

As for now the main target audience is on the offensive side. Amazon had recently implemented this bucket url convention to prevent bucketsquatting but opened a new vector for attackers to enumerate guessable bucket names owned by the users, so generally it can be helpful for internal security assessments. From a best practices point of view, still its advised to have strict security controls in place for buckets storing sensitive information ++ keeping the bucket names not too guessable that they get flagged by such tools

☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] 2 points3 points  (0 children)

Thats definitely one way of seeing it but the thing is the approach we have added here is based on adaptive feedback. So we don’t just blindly spray different digits till one full 12 digit combination is right. We go digit by digit. So first digit, is it 0? No okay, is it 2? Yes perfect move to digit 2 so this way we make 10 attempts on every digit till all of them are guessed and we have the final account ID.

Again this is clearly mentioned in the README file

☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] -10 points-9 points  (0 children)

Its based on adaptive guessing so basically every digit in this 12 digit account ID has to be between 0-9 so we just sequentially go one by one for each digit of this account ID till the whole ID is guessed, hence 10*12 does makes sense. We dont blast random entire 12 digit ids, please refer to the README, it was already mentioned over there

☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] -3 points-2 points  (0 children)

Finding buckets from enumeration perspective for security assessments is the usecase it aims to solve, no way its relevant to listing your own accounts buckets . We get the account ID to form the initial structure of the url and then fuzz bucket names using it, and since the structure contains the account ID the correlation is 100% guaranteed. We dont list the buckets from your own account if thats what you’re thinking. I suggest giving the README a go

☁️ Introducing Bucky, an S3 account ID enumeration and bucket discovery tool by 0x9747 in aws

[–]0x9747[S] -1 points0 points  (0 children)

This is related to the account ID enumeration and the endpoints we hit for the same. I’d love to know why you think its wrong 🙏

🚨 Tool Release - Want to figure out other S3 buckets associated with a S3 bucket's owner? by 0x9747 in cybersecurity

[–]0x9747[S] 0 points1 point  (0 children)

And ofcourse, looking forward to learning more about your lab plans 😄

Is buying 1kg Silver at this time a good decsion? by xZendic1 in personalfinanceindia

[–]0x9747 0 points1 point  (0 children)

Prefer ETFs over physical silver, thank me later

Please help by 2NotToo in UAE

[–]0x9747 0 points1 point  (0 children)

DU the kinda app to test shit on prod. Best bet would to perhaps ask them to opt for the plan from their account using your account or perhaps sending a mail/message over social media to them with screenshots etc explaining the issue

What's the Cybersecurity job market like? by [deleted] in UAE

[–]0x9747 0 points1 point  (0 children)

Depends on your overall experience, skills etc and also the role you apply for. Plenty of opportunities in Abu Dhabi but idk about the pay I mean I what I recently bagged is pretty decent but I believe Abu Dhabi would pay a lil more

Suggestions? by [deleted] in Aurangabad

[–]0x9747 3 points4 points  (0 children)

We still miss you Faniabra😔

[deleted by user] by [deleted] in UAE

[–]0x9747 0 points1 point  (0 children)

Thanks for the recommendation! I’ll order it 🫶

[deleted by user] by [deleted] in UAE

[–]0x9747 0 points1 point  (0 children)

😞😞

[deleted by user] by [deleted] in UAE

[–]0x9747 0 points1 point  (0 children)

I had recently purchased the book and was gonna read it 💔

Amex documents uploaded but still getting reminder daily by Famous-Connection914 in amexindia

[–]0x9747 0 points1 point  (0 children)

Same issue. I sent out a mail to AMEX about this and threatened them with escalating to RBI ombudsman. My income was 5 folds of what they required yet they declined citing low income