2022-07-03 20:40:55 +08:00
|
|
|
|

|
2022-03-08 23:17:17 +08:00
|
|
|
|
|
2022-08-18 17:55:40 +08:00
|
|
|
|
# 问题解决ModuleNotFoundError: No module named 'urlparse'
|
|
|
|
|
|
|
|
|
|
|
|

|
|
|
|
|
|
|
2022-08-18 17:58:03 +08:00
|
|
|
|
如果遇到这个问题,可以使用以下命令,如果还是无法解决,可以通过issue的方式联系我,或者发送邮件到`uzjuer@163.com`或在我的GitHub主页添加我的微信,告诉我python版本即可
|
2022-08-18 17:55:40 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
|
pip3 install cos-python-sdk-v5
|
|
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
目前我已经测试可以运行的版本如下
|
|
|
|
|
|
|
|
|
|
|
|
1、python3.8.9
|
|
|
|
|
|
|
|
|
|
|
|
2、python3.9.13
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# :rooster:使用教程
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
|
git clone https://github.com/UzJu/Cloud-Bucket-Leak-Detection-Tools.git
|
2022-07-16 15:38:39 +08:00
|
|
|
|
cd Cloud-Bucket-Leak-Detection-Tools/
|
|
|
|
|
|
# 安装依赖 建议使用Python3.8以上的版本 我的版本: Python 3.9.13 (main, May 24 2022, 21:28:31)
|
|
|
|
|
|
pip3 install huaweicloud-sdk-python
|
|
|
|
|
|
pip3 install -r requirements.txt
|
2022-03-04 19:16:52 +08:00
|
|
|
|
python3 main.py -h
|
|
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
使用之前需要在`config/conf.py`文件配置自己对应的云厂商AK
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 1、阿里云存储桶
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.1、单个存储桶检测
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -aliyun [存储桶URL]
|
|
|
|
|
|
```
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.2、自动存储桶劫持
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
当如果检测存储桶不存在时会自动劫持该存储桶
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.3、批量存储桶地址检测
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# fofa语法
|
2022-03-06 21:28:14 +08:00
|
|
|
|
domain="aliyuncs.com"
|
2022-07-16 15:38:39 +08:00
|
|
|
|
server="AliyunOSS"domain="aliyuncs.com"
|
2022-03-06 21:28:14 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# 使用-faliyun
|
|
|
|
|
|
python3 main.py -faliyun url.txt
|
2022-03-06 21:28:14 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 2、腾讯云存储桶
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
python3 main.py -tcloud [存储桶地址]
|
2022-05-29 14:07:45 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 3、华为云存储桶
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -hcloud [存储桶地址]
|
|
|
|
|
|
```
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 4、AWS存储桶
|
2022-03-07 23:23:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -aws [存储桶地址]
|
|
|
|
|
|
```
|
2022-03-07 23:23:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 5、扫描结果保存
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
扫描结果会存放在`results`目录下
|
2022-07-03 20:40:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-07-03 20:40:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# :cop:0xFFFFFFFF 免责声明
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
|
|
|
|
|
1、本工具只作为学术交流,禁止使用工具做违法的事情
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-03-06 21:28:14 +08:00
|
|
|
|
2、只是写着玩
|
2022-03-07 23:58:40 +08:00
|
|
|
|
|
|
|
|
|
|
3、我的微信
|
|
|
|
|
|
|
|
|
|
|
|
> 如果你有更好的建议或者交个朋友
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
<img src="images/157070417-dbb7886f-1bb8-412f-a30b-0f85bc8ffa10.png" alt="image" style="zoom:33%;" />
|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
4、博客: UzzJu.com
|
|
|
|
|
|
5、公众号
|
|
|
|
|
|
|
|
|
|
|
|

|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# 曲线图
|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
[](https://starchart.cc/UzJu/Cloud-Bucket-Leak-Detection-Tools)
|