forked from projectdiscovery/nuclei-templates
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathaws-bucket-takeover.yaml
More file actions
85 lines (78 loc) · 2.41 KB
/
aws-bucket-takeover.yaml
File metadata and controls
85 lines (78 loc) · 2.41 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
id: aws-bucket-takeover
info:
name: AWS Bucket Takeover Detection
author: pdteam,pwnhxl,zy9ard3,venjaku
severity: high
description: AWS Bucket takeover was detected.
reference:
- https://github.com/EdOverflow/can-i-take-over-xyz/issues/36
metadata:
max-request: 1
tags: takeover,aws,bucket,vuln
http:
- method: GET
path:
- "{{BaseURL}}"
matchers-condition: and
matchers:
- type: dsl
dsl:
- Host != ip
- type: word
words:
- "The specified bucket does not exist"
- "BucketName"
condition: and
- type: dsl
dsl:
- contains(tolower(header), 'x-guploader-uploadid')
- contains(tolower(header), "aliyunoss")
negative: true
- type: regex
part: host
regex:
- '^[a-z0-9][a-z0-9-]+-[0-9]{12}-[a-z0-9-]+-an\.s3\.[a-z0-9-]+\.amazonaws\.com'
negative: true
- type: word
part: host
words:
- "amazonaws.com"
- "ks3.ksyun.com"
- "kss.ksyun.com"
- "kss3.ksyun.com"
- "ks3-cn-beijing.ksyun.com"
- "ks3-cn-guangzhou.ksyun.com"
- "ks3-cn-hk-1.ksyun.com"
- "ks3-cn-shanghai.ksyun.com"
- "ks3-jr-beijing.ksyun.com"
- "ks3-jr-shanghai.ksyun.com"
- "ks3-rus.ksyun.com"
- "ks3-sgp.ksyun.com"
- "obs.jrzq.huaweicloud.com"
- "obs.petalpay.huaweicloud.com"
- "oss-cn-hangzhou.aliyuncs.com"
- "oss-cn-shanghai.aliyuncs.com"
- "oss-cn-qingdao.aliyuncs.com"
- "oss-cn-beijing.aliyuncs.com"
- "oss-cn-zhangjiakou.aliyuncs.com"
- "oss-cn-huhehaote.aliyuncs.com"
- "oss-cn-shenzhen.aliyuncs.com"
- "oss-cn-hongkong.aliyuncs.com"
- "oss-us-west-1.aliyuncs.com"
- "oss-us-east-1.aliyuncs.com"
- "oss-ap-southeast-1.aliyuncs.com"
- "oss-ap-southeast-2.aliyuncs.com"
- "oss-ap-southeast-3.aliyuncs.com"
- "oss-ap-southeast-5.aliyuncs.com"
- "oss-ap-south-1.aliyuncs.com"
- "oss-ap-northeast-1.aliyuncs.com"
- "oss-eu-central-1.aliyuncs.com"
- "oss-me-east-1.aliyuncs.com"
negative: true
extractors:
- type: regex
part: body
group: 1
regex:
- '<li>BucketName: (.*?)</li>'
- '<BucketName>(.*?)</BucketName>'