This new open-source tool is hunting for public AWS S3 buckets to spy on

Cloud Security
(Image credit: laymanzoom / Shutterstock)

Cloud misconfigurations are one of the biggest causes of data breaches these days, and one security researcher has now set out to fix it with a new tool.

Built on Python, S3crets Scanner allows security researchers and analysts to look for “secrets” that companies exposed to the public, by mistake, through their company’s AWS S3 storage buckets.

As explained by BleepingComputer, secrets include authentication keys, access tokens, or API keys, all of which can be used by threat actors to deal plenty of damage. For example, these secrets can be used to access the company’s corporate network and endpoints, which could result in data theft, malware infections, or even ransomware attacks. 

Targeting PII

The tool was built by security researcher Eilon Harel to only look for secrets exposed by mistake. It does so by only scanning S3 buckets that have specific configurations set to false, such as “BlockPublicAcls”, “BlockPublicPolicy”, “IgnorePublicAcls”, and “RestrictPublicBuckets”. Any other buckets are filtered out. 

Buckets that match the above criteria will be downloaded as text files, and scanned using the Trufflehog3 tool which checks for credentials and private keys on S3 buckets, but also GitHub, GitLab, and filesystems. Harel created a unique set of rules for Trufflehog3, which targets personally identifiable information (PII) exposure, as well as internal access tokens. 

Harel believes the tool can help businesses expose fewer secrets, consequently suffering fewer data leaks and similar cybersecurity incidents. He also believes it can be used for white-hat operations, as researchers can scan publicly accessible buckets for misconfigurations and notify the businesses before bad actors.

A multi-cloud environment is essential for businesses these days, but securing data in such a system is one of the biggest challenges they face. A recent report by cybersecurity experts Radware states that 70% of senior execs, DevOps leaders, and other seniors, aren’t confident they can properly secure both on-prem and multi-cloud environments. 

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Shadowed hands on a digital background reaching for a login prompt.
Private API keys and passwords found in AI training dataset - nearly 12,000 details leaked
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
AWS S3 feature abused by ransomware hackers to encrypt storage buckets
Stress
Time tracker tool spilled details on remote workers - millions of screenshots leaked
Data Breach
Thousands of widely-used public workspaces are leaking data
Illustration of a hooked email hovering over a mobile phone
AWS misconfigurations reportedly used to launch phishing attacks
Concept art representing cybersecurity principles
“Everything starts with security" - AWS CISO on how making security simple can be the key to safety
Latest in Pro
US flags
US government IT contracts set to be centralized in new Trump order
Google Gemini AI
Gmail is adding a new Gemini AI tool to help smarten up your work emails
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
Closing the cybersecurity skills gap
How CISOs can meet the demands of new privacy regulations
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Latest in News
A phone showing a ChatGPT app error message
ChatGPT is down for many – here's what's going on
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
US flags
US government IT contracts set to be centralized in new Trump order
Tesla Roadster 2
Tesla is still taking deposits on its long overdue Roadster, despite promising it would arrive in 2020
Samsung HW-Q990D soundbar with Halloween theme over the top
Samsung promises to repair soundbars bricked by its disastrous software update for free – but it'll probably involve shipping