aws-s3-bucket.md (6716B)
1 --- 2 title: "AWS - Service - S3 Buckets" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-s3-bucket.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-s3-bucket.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - Service - S3 Buckets 12 13 An AWS S3 bucket is a cloud-based storage container that holds files, known as objects, which can be accessed over the internet. It is highly scalable and can store large amounts of data, such as documents, images, and backups. S3 provides robust security through access control, encryption, and permissions management. It ensures high durability and availability, making it ideal for storing and retrieving data from anywhere. 14 15 ## Tools 16 17 * [aws/aws-cli](https://github.com/aws/aws-cli) - Universal Command Line Interface for Amazon Web Services 18 19 ```ps1 20 sudo apt install awscli 21 ``` 22 23 * [digi.ninja/bucket-finder](https://digi.ninja/projects/bucket_finder.php) - Search for public buckets, list and download all files if directory indexing is enabled 24 25 ```powershell 26 wget https://digi.ninja/files/bucket_finder_1.1.tar.bz2 -O bucket_finder_1.1.tar.bz2 27 ./bucket_finder.rb my_words 28 ./bucket_finder.rb --region ie my_words 29 ./bucket_finder.rb --download --region ie my_words 30 ./bucket_finder.rb --log-file bucket.out my_words 31 ``` 32 33 * [aws-sdk/boto3](https://boto3.amazonaws.com/v1/documentation/api/latest/index.html) - Amazon Web Services (AWS) SDK for Python 34 35 ```python 36 import boto3 37 s3 = boto3.client('s3',aws_access_key_id='AKIAJQDP3RKREDACTED',aws_secret_access_key='igH8yFmmpMbnkcUaCqXJIRIozKVaREDACTED',region_name='us-west-1') 38 39 try: 40 result = s3.list_buckets() 41 print(result) 42 except Exception as e: 43 print(e) 44 ``` 45 46 * [nccgroup/s3_objects_check](https://github.com/nccgroup/s3_objects_check) - Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files 47 48 ```powershell 49 python3 -m venv env && source env/bin/activate 50 pip install -r requirements.txt 51 python s3-objects-check.py -h 52 python s3-objects-check.py -p whitebox-profile -e blackbox-profile 53 ``` 54 55 * [grayhatwarfare/buckets](https://buckets.grayhatwarfare.com/) - Search Public Buckets 56 57 ## Credentials and Profiles 58 59 Create a profile with your `AWSAccessKeyId` and `AWSSecretKey`, then you can use `--profile nameofprofile` in the `aws` command. 60 61 ```js 62 aws configure --profile nameofprofile 63 AWS Access Key ID [None]: <AWSAccessKeyId> 64 AWS Secret Access Key [None]: <AWSSecretKey> 65 Default region name [None]: 66 Default output format [None]: 67 ``` 68 69 Alternatively you can use environment variables instead of creating a profile. 70 71 ```bash 72 export AWS_ACCESS_KEY_ID=ASIAZ[...]PODP56 73 export AWS_SECRET_ACCESS_KEY=fPk/Gya[...]4/j5bSuhDQ 74 export AWS_SESSION_TOKEN=FQoGZXIvYXdzE[...]8aOK4QU= 75 ``` 76 77 ## Public S3 Bucket 78 79 An open S3 bucket refers to an Amazon Simple Storage Service (Amazon S3) bucket that has been configured to allow public access, either intentionally or by mistake. This means that anyone on the internet could potentially access, read, or even modify the data stored in the bucket, depending on the permissions set. 80 81 * `http://s3.amazonaws.com/<bucket-name>` 82 * `http://<bucket-name>.s3.amazonaws.com` 83 * `https://<bucket-name>.region.amazonaws.com/<file>` 84 85 AWS S3 buckets name examples: [http://flaws.cloud.s3.amazonaws.com](http://flaws.cloud.s3.amazonaws.com). 86 87 Either bruteforce the buckets name with keyword related to your target or search through the leaked one using OSINT tool such as [buckets.grayhatwarfare.com](https://buckets.grayhatwarfare.com/). 88 89 When file listing is enabled, the name is also displayed inside the `<Name>` XML tag. 90 91 ```xml 92 <ListBucketResult xmlns="http://s3.amazonaws.com/doc/2006-03-01/"> 93 <Name>adobe-REDACTED-REDACTED-REDACTED</Name> 94 ``` 95 96 ## Bucket Interations 97 98 ### Find the Region 99 100 To find the region of an Amazon Web Services (AWS) service (such as an S3 bucket) using dig or nslookup, query the DNS records for the service's domain or endpoint. 101 102 ```bash 103 $ dig flaws.cloud 104 ;; ANSWER SECTION: 105 flaws.cloud. 5 IN A 52.218.192.11 106 107 $ nslookup 52.218.192.11 108 Non-authoritative answer: 109 11.192.218.52.in-addr.arpa name = s3-website-us-west-2.amazonaws.com. 110 ``` 111 112 ### List Files 113 114 To list files in an AWS S3 bucket using the AWS CLI, you can use the following command: 115 116 ```bash 117 aws s3 ls <target> [--options] 118 aws s3 ls s3://bucket-name --no-sign-request --region <insert-region-here> 119 aws s3 ls s3://flaws.cloud/ --no-sign-request --region us-west-2 120 ``` 121 122 ### Copy, Upload and Download Files 123 124 * **Copy** 125 126 ```bash 127 aws s3 cp <source> <target> [--options] 128 aws s3 cp local.txt s3://bucket-name/remote.txt --acl authenticated-read 129 aws s3 cp login.html s3://bucket-name --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers 130 ``` 131 132 * **Upload** 133 134 ```bash 135 aws s3 mv <source> <target> [--options] 136 aws s3 mv test.txt s3://hackerone.files 137 SUCCESS : "move: ./test.txt to s3://hackerone.files/test.txt" 138 ``` 139 140 * **Download** 141 142 ```bash 143 aws s3 sync <source> <target> [--options] 144 aws s3 sync s3://level3-9afd3927f195e10225021a578e6f78df.flaws.cloud/ . --no-sign-request --region us-west-2 145 ``` 146 147 ### List File Versions 148 149 When versioning is enabled in an AWS S3 bucket, list file history using the AWS CLI: 150 151 ```bash 152 aws s3api list-object-versions --bucket <bucket-name> [--options] 153 aws s3api list-object-versions --bucket <bucket-name> --prefix <file-path> 154 ``` 155 156 ### Download a Specific File Version 157 158 ```bash 159 aws s3api get-object --bucket <bucket-name> --key <source> --version-id <id> <target> 160 ``` 161 162 ## References 163 164 * [There's a Hole in 1,951 Amazon S3 Buckets - Mar 27, 2013 - Rapid7 willis](https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets) 165 * [Bug Bounty Survey - AWS Basic test](https://web.archive.org/web/20180808181450/https://twitter.com/bugbsurveys/status/860102244171227136) 166 * [flaws.cloud Challenge based on AWS vulnerabilities - Scott Piper - Summit Route](http://flaws.cloud/) 167 * [flaws2.cloud Challenge based on AWS vulnerabilities - Scott Piper - Summit Route](http://flaws2.cloud) 168 * [Guardzilla video camera hardcoded AWS credential - INIT_6 - December 27, 2018](https://blackmarble.sh/guardzilla-video-camera-hard-coded-aws-credentials/) 169 * [AWS PENETRATION TESTING PART 1. S3 BUCKETS - VirtueSecurity](https://www.virtuesecurity.com/aws-penetration-testing-part-1-s3-buckets/) 170 * [AWS PENETRATION TESTING PART 2. S3, IAM, EC2 - VirtueSecurity](https://www.virtuesecurity.com/aws-penetration-testing-part-2-s3-iam-ec2/) 171 * [A Technical Analysis of the Capital One Hack - CloudSploit - Aug 2 2019](https://blog.cloudsploit.com/a-technical-analysis-of-the-capital-one-hack-a9b43d7c8aea?gi=8bb65b77c2cf)