PWNEDLABS Identify the AWS Account ID from a Public S3 Bucket
Real-world context
Nmap
nmap -Pn 54.204.171.32
Starting Nmap 7.94SVN ( https://nmap.org ) at 2024-03-07 01:33 EET
Nmap scan report for ec2-54-204-171-32.compute-1.amazonaws.com (54.204.171.32)
Host is up (0.13s latency).
Not shown: 999 filtered tcp ports (no-response)
PORT STATE SERVICE
80/tcp open http
Nmap done: 1 IP address (1 host up) scanned in 14.86 secondsAccess the website
https://mega-big-tech.s3.amazonaws.com/images/workpro1.jpgAccess the S3 Bucket
Do connect with the received AWS account
Install and use s3-account-search
Find S3 Bucket Region
Log into the AWS management console in your own personal AWS account and make sure that the us-east-1 region is selected.
us-east-1 region is selected.Last updated