2022-07-03 20:40:55 +08:00
|
|
|
|

|
2022-03-08 23:17:17 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# :rooster:使用教程
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
|
|
|
|
|
git clone https://github.com/UzJu/Cloud-Bucket-Leak-Detection-Tools.git
|
2022-07-16 15:38:39 +08:00
|
|
|
|
cd Cloud-Bucket-Leak-Detection-Tools/
|
|
|
|
|
|
# 安装依赖 建议使用Python3.8以上的版本 我的版本: Python 3.9.13 (main, May 24 2022, 21:28:31)
|
2022-08-21 16:44:18 +08:00
|
|
|
|
# 已经测试版本如下
|
|
|
|
|
|
# 1、python3.8.9
|
|
|
|
|
|
# 2、python3.9.13
|
|
|
|
|
|
# 3、python3.7
|
2022-08-21 17:06:35 +08:00
|
|
|
|
# 4、python3.6.15
|
|
|
|
|
|
# 5、python3.9.6
|
2022-07-16 15:38:39 +08:00
|
|
|
|
pip3 install -r requirements.txt
|
2022-03-04 19:16:52 +08:00
|
|
|
|
python3 main.py -h
|
|
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
使用之前需要在`config/conf.py`文件配置自己对应的云厂商AK
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 1、阿里云存储桶
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.1、单个存储桶检测
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -aliyun [存储桶URL]
|
|
|
|
|
|
```
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.2、自动存储桶劫持
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
当如果检测存储桶不存在时会自动劫持该存储桶
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
### 1.3、批量存储桶地址检测
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# fofa语法
|
2022-03-06 21:28:14 +08:00
|
|
|
|
domain="aliyuncs.com"
|
2022-07-16 15:38:39 +08:00
|
|
|
|
server="AliyunOSS"domain="aliyuncs.com"
|
2022-03-06 21:28:14 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# 使用-faliyun
|
|
|
|
|
|
python3 main.py -faliyun url.txt
|
2022-03-06 21:28:14 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 2、腾讯云存储桶
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
|
|
|
|
|
```bash
|
2022-07-16 15:38:39 +08:00
|
|
|
|
python3 main.py -tcloud [存储桶地址]
|
2022-05-29 14:07:45 +08:00
|
|
|
|
```
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 3、华为云存储桶
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -hcloud [存储桶地址]
|
|
|
|
|
|
```
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 4、AWS存储桶
|
2022-03-07 23:23:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
```bash
|
|
|
|
|
|
python3 main.py -aws [存储桶地址]
|
|
|
|
|
|
```
|
2022-03-07 23:23:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
## 5、扫描结果保存
|
2022-05-29 14:07:45 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
扫描结果会存放在`results`目录下
|
2022-07-03 20:40:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-07-03 20:40:55 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|

|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# :cop:0xFFFFFFFF 免责声明
|
2022-03-06 21:28:14 +08:00
|
|
|
|
|
|
|
|
|
|
1、本工具只作为学术交流,禁止使用工具做违法的事情
|
2022-03-04 19:16:52 +08:00
|
|
|
|
|
2022-03-06 21:28:14 +08:00
|
|
|
|
2、只是写着玩
|
2022-03-07 23:58:40 +08:00
|
|
|
|
|
|
|
|
|
|
3、我的微信
|
|
|
|
|
|
|
|
|
|
|
|
> 如果你有更好的建议或者交个朋友
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
<img src="images/157070417-dbb7886f-1bb8-412f-a30b-0f85bc8ffa10.png" alt="image" style="zoom:33%;" />
|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
4、博客: UzzJu.com
|
|
|
|
|
|
5、公众号
|
|
|
|
|
|
|
|
|
|
|
|

|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-08-25 17:29:17 +08:00
|
|
|
|
## 404星链计划
|
2022-08-25 17:31:28 +08:00
|
|
|
|

|
2022-08-25 17:29:17 +08:00
|
|
|
|
|
|
|
|
|
|
**Cloud-Bucket-Leak-Detection-Tools** 现已加入 [404星链计划](https://github.com/knownsec/404StarLink)
|
|
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
# 曲线图
|
2022-03-08 20:48:39 +08:00
|
|
|
|
|
2022-07-16 15:38:39 +08:00
|
|
|
|
[](https://starchart.cc/UzJu/Cloud-Bucket-Leak-Detection-Tools)
|