Posts

Showing posts from September, 2019

Hacking AWS S3 bucket

Image
Hi Guys, So, It’s been a while since I’ve blogged last time. It’s because I’m busy with my work, let's get into the field. Now, before proceeding further onto this, we must know about AWS and its use.  Amazon Simple Storage Service is storage for the Internet. Amazon S3 has a simple web services interface that you can use to store and retrieve any amount of data, at any time, from anywhere on the web. You will get free subscription to your AWS account for a year when you register for the first time. before you apply your hacking skills on any website, you must know about the technology in which the application is built, for that you can choose server and framework fingerprinting or simple nmap or netcat scan. For privacy concern, I’m not gonna disclose the site name which I hacked AWS S3 bucket. So, let’s call it as  examplesite.com.   I was crawling the site. Started with robots.txt ‘www.examplesite.com/robots.txt’ (in case if you don’t know what’s robots.txt,