daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-s3-bucket.md (6716B)


      1 ---
      2 title: "AWS - Service - S3 Buckets"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-s3-bucket.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-s3-bucket.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Service - S3 Buckets
     12 
     13 An AWS S3 bucket is a cloud-based storage container that holds files, known as objects, which can be accessed over the internet. It is highly scalable and can store large amounts of data, such as documents, images, and backups. S3 provides robust security through access control, encryption, and permissions management. It ensures high durability and availability, making it ideal for storing and retrieving data from anywhere.
     14 
     15 ## Tools
     16 
     17 * [aws/aws-cli](https://github.com/aws/aws-cli) - Universal Command Line Interface for Amazon Web Services
     18 
     19  ```ps1
     20  sudo apt install awscli
     21  ```
     22 
     23 * [digi.ninja/bucket-finder](https://digi.ninja/projects/bucket_finder.php) - Search for public buckets, list and download all files if directory indexing is enabled
     24 
     25  ```powershell
     26  wget https://digi.ninja/files/bucket_finder_1.1.tar.bz2 -O bucket_finder_1.1.tar.bz2
     27  ./bucket_finder.rb my_words
     28  ./bucket_finder.rb --region ie my_words
     29  ./bucket_finder.rb --download --region ie my_words
     30  ./bucket_finder.rb --log-file bucket.out my_words
     31  ```
     32 
     33 * [aws-sdk/boto3](https://boto3.amazonaws.com/v1/documentation/api/latest/index.html) - Amazon Web Services (AWS) SDK for Python
     34 
     35  ```python
     36  import boto3
     37  s3 = boto3.client('s3',aws_access_key_id='AKIAJQDP3RKREDACTED',aws_secret_access_key='igH8yFmmpMbnkcUaCqXJIRIozKVaREDACTED',region_name='us-west-1')
     38 
     39  try:
     40   result = s3.list_buckets()
     41   print(result)
     42  except Exception as e:
     43   print(e)
     44  ```
     45 
     46 * [nccgroup/s3_objects_check](https://github.com/nccgroup/s3_objects_check) - Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files
     47 
     48     ```powershell
     49     python3 -m venv env && source env/bin/activate
     50     pip install -r requirements.txt
     51     python s3-objects-check.py -h
     52     python s3-objects-check.py -p whitebox-profile -e blackbox-profile
     53     ```
     54 
     55 * [grayhatwarfare/buckets](https://buckets.grayhatwarfare.com/) - Search Public Buckets
     56 
     57 ## Credentials and Profiles
     58 
     59 Create a profile with your `AWSAccessKeyId` and `AWSSecretKey`, then you can use `--profile nameofprofile` in the `aws` command.
     60 
     61 ```js
     62 aws configure --profile nameofprofile
     63 AWS Access Key ID [None]: <AWSAccessKeyId>
     64 AWS Secret Access Key [None]: <AWSSecretKey>
     65 Default region name [None]: 
     66 Default output format [None]: 
     67 ```
     68 
     69 Alternatively you can use environment variables instead of creating a profile.
     70 
     71 ```bash
     72 export AWS_ACCESS_KEY_ID=ASIAZ[...]PODP56
     73 export AWS_SECRET_ACCESS_KEY=fPk/Gya[...]4/j5bSuhDQ
     74 export AWS_SESSION_TOKEN=FQoGZXIvYXdzE[...]8aOK4QU=
     75 ```
     76 
     77 ## Public S3 Bucket
     78 
     79 An open S3 bucket refers to an Amazon Simple Storage Service (Amazon S3) bucket that has been configured to allow public access, either intentionally or by mistake. This means that anyone on the internet could potentially access, read, or even modify the data stored in the bucket, depending on the permissions set.
     80 
     81 * `http://s3.amazonaws.com/<bucket-name>`
     82 * `http://<bucket-name>.s3.amazonaws.com`
     83 * `https://<bucket-name>.region.amazonaws.com/<file>`
     84 
     85 AWS S3 buckets name examples: [http://flaws.cloud.s3.amazonaws.com](http://flaws.cloud.s3.amazonaws.com).
     86 
     87 Either bruteforce the buckets name with keyword related to your target or search through the leaked one using OSINT tool such as [buckets.grayhatwarfare.com](https://buckets.grayhatwarfare.com/).
     88 
     89 When file listing is enabled, the name is also displayed inside the `<Name>` XML tag.
     90 
     91 ```xml
     92 <ListBucketResult xmlns="http://s3.amazonaws.com/doc/2006-03-01/">
     93 <Name>adobe-REDACTED-REDACTED-REDACTED</Name>
     94 ```
     95 
     96 ## Bucket Interations
     97 
     98 ### Find the Region
     99 
    100 To find the region of an Amazon Web Services (AWS) service (such as an S3 bucket) using dig or nslookup, query the DNS records for the service's domain or endpoint.
    101 
    102 ```bash
    103 $ dig flaws.cloud
    104 ;; ANSWER SECTION:
    105 flaws.cloud.    5    IN    A    52.218.192.11
    106 
    107 $ nslookup 52.218.192.11
    108 Non-authoritative answer:
    109 11.192.218.52.in-addr.arpa name = s3-website-us-west-2.amazonaws.com.
    110 ```
    111 
    112 ### List Files
    113 
    114 To list files in an AWS S3 bucket using the AWS CLI, you can use the following command:
    115 
    116 ```bash
    117 aws s3 ls <target> [--options]
    118 aws s3 ls s3://bucket-name --no-sign-request --region <insert-region-here>
    119 aws s3 ls s3://flaws.cloud/ --no-sign-request --region us-west-2
    120 ```
    121 
    122 ### Copy, Upload and Download Files
    123 
    124 * **Copy**
    125 
    126  ```bash
    127  aws s3 cp <source> <target> [--options]
    128  aws s3 cp local.txt s3://bucket-name/remote.txt --acl authenticated-read
    129  aws s3 cp login.html s3://bucket-name --grants read=uri=http://acs.amazonaws.com/groups/global/AllUsers
    130  ```
    131 
    132 * **Upload**
    133 
    134  ```bash
    135  aws s3 mv <source> <target> [--options]
    136  aws s3 mv test.txt s3://hackerone.files
    137  SUCCESS : "move: ./test.txt to s3://hackerone.files/test.txt"
    138  ```
    139 
    140 * **Download**
    141 
    142  ```bash
    143  aws s3 sync <source> <target> [--options]
    144  aws s3 sync s3://level3-9afd3927f195e10225021a578e6f78df.flaws.cloud/ . --no-sign-request --region us-west-2
    145  ```
    146 
    147 ### List File Versions
    148 
    149 When versioning is enabled in an AWS S3 bucket, list file history using the AWS CLI:
    150 
    151 ```bash
    152 aws s3api list-object-versions --bucket <bucket-name> [--options]
    153 aws s3api list-object-versions --bucket <bucket-name> --prefix <file-path>
    154 ```
    155 
    156 ### Download a Specific File Version
    157 
    158 ```bash
    159 aws s3api get-object --bucket <bucket-name> --key <source> --version-id <id> <target>
    160 ```
    161 
    162 ## References
    163 
    164 * [There's a Hole in 1,951 Amazon S3 Buckets - Mar 27, 2013 - Rapid7 willis](https://community.rapid7.com/community/infosec/blog/2013/03/27/1951-open-s3-buckets)
    165 * [Bug Bounty Survey - AWS Basic test](https://web.archive.org/web/20180808181450/https://twitter.com/bugbsurveys/status/860102244171227136)
    166 * [flaws.cloud Challenge based on AWS vulnerabilities - Scott Piper - Summit Route](http://flaws.cloud/)
    167 * [flaws2.cloud Challenge based on AWS vulnerabilities - Scott Piper - Summit Route](http://flaws2.cloud)
    168 * [Guardzilla video camera hardcoded AWS credential - INIT_6 - December 27, 2018](https://blackmarble.sh/guardzilla-video-camera-hard-coded-aws-credentials/)
    169 * [AWS PENETRATION TESTING PART 1. S3 BUCKETS - VirtueSecurity](https://www.virtuesecurity.com/aws-penetration-testing-part-1-s3-buckets/)
    170 * [AWS PENETRATION TESTING PART 2. S3, IAM, EC2 - VirtueSecurity](https://www.virtuesecurity.com/aws-penetration-testing-part-2-s3-iam-ec2/)
    171 * [A Technical Analysis of the Capital One Hack - CloudSploit - Aug 2 2019](https://blog.cloudsploit.com/a-technical-analysis-of-the-capital-one-hack-a9b43d7c8aea?gi=8bb65b77c2cf)