S3
Enumerate misconfigured CloudFront Origins for Public S3 Buckets
1) DNS Enumeration
nslookup domain.org
nslookup IP_ADDRESS
nslookup subdomain.domain.org
nslookup assets.domain.org.s3.amazonaws.com2) Subdomain enumeration
org: domain.org site: s3.amazonaws.com3) Web Page Source Inspection
Right-Click -> View Page Source
CTRL+F -> s3.amazonaws.comExploit S3 Buckets
1) Unauthenticated S3 Bucket dumping
2) Bucket enumeration
3) Download a file from a bucket
4) Enumerate bucket policies
Exploit Services that are paired/used with S3
EC2
1) Generate AMI from image
2) Create your SSH key pair
3) Describe Subnets
4) Describe available security groups
5) Create EC2 instance from AMI
6) SSH to instance
Last updated