SOC 직업 분류 기준
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill wstg-conf-11명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SKILL.md 표시 중
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
| name | wstg-conf-11 |
| description | Test Cloud Storage |
| category | configuration |
| owasp_id | WSTG-CONF-11 |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["misconfiguration","hardening","server","wstg","conf"] |
| tech_stack | [] |
| cwe_ids | ["CWE-16"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
WSTG-CONF-11
Test Cloud Storage
Cloud storage services (AWS S3, Azure Blob Storage, Google Cloud Storage) are commonly used to store application data, backups, and static assets. Misconfigured access controls can expose sensitive data to unauthorized users or allow arbitrary file uploads. This test identifies publicly accessible buckets, overly permissive ACLs, and other cloud storage misconfigurations.
| Provider | Service | URL Pattern |
|---|---|---|
| AWS | S3 | bucket.s3.amazonaws.com |
| Azure | Blob Storage | account.blob.core.windows.net |
| Cloud Storage | storage.googleapis.com/bucket | |
| DigitalOcean | Spaces | bucket.region.digitaloceanspaces.com |
# Check for S3 references in source code
curl -s https://target.com | grep -oP 's3\.amazonaws\.com[^"'"'"' ]*'
curl -s https://target.com | grep -oP '[a-z0-9-]+\.s3\.[a-z0-9-]+\.amazonaws\.com'
# Check for Azure Blob
curl -s https://target.com | grep -oP '[a-z0-9]+\.blob\.core\.windows\.net[^"'"'"
curl -s https://target.com | grep -oP
curl -s https://target.com | grep -oP
# Test read access (unauthenticated)
curl -s https://bucket-name.s3.amazonaws.com/
# List bucket contents
curl -s "https://bucket-name.s3.amazonaws.com/?list-type=2"
# Try to read specific object
curl -s https://bucket-name.s3.amazonaws.com/test.txt
# Test write access
curl -X PUT -d "test" https://bucket-name.s3.amazonaws.com/test.txt
# List bucket contents (no auth)
aws s3 ls s3://bucket-name --no-sign-request
# List with authenticated access
aws s3 ls s3://bucket-name
# Try to copy file
aws s3 cp test.txt s3://bucket-name/ --no-sign-request
# Try to download
aws s3 cp s3://bucket-name/file.txt ./downloaded.txt --no-sign-request
# Check bucket ACL
aws s3api get-bucket-acl --bucket bucket-name --no-sign-request
# List containers
curl -s "https://account.blob.core.windows.net/?comp=list"
# List blobs in container
curl -s "https://account.blob.core.windows.net/container?restype=container&comp=list"
# Access specific blob
curl -s "https://account.blob.core.windows.net/container/blob.txt"
# Check for anonymous access
az storage blob list --account-name account --container-name container --auth-mode anonymous
# List bucket
curl -s "https://storage.googleapis.com/bucket-name"
curl -s "https://storage.googleapis.com/storage/v1/b/bucket-name/o"
# Access object
curl -s "https://storage.googleapis.com/bucket-name/object.txt"
# gsutil commands
gsutil ls gs://bucket-name
gsutil cp gs://bucket-name/file.txt ./
# Common naming patterns
company="targetcompany"
patterns=(
"$company"
"${company}-dev"
"${company}-staging"
"${company}-prod"
"${company}-backup"
"${company}-uploads"
"${company}-data"
"${company}-assets"
"${company}-media"
"${company}-logs"
)
for bucket in "${patterns[@]}"; do
status=$(curl -s -o /dev/null -w "%{http_code}" "https://${bucket}.s3.amazonaws.com")
if [ "$status" != "404" ]; then
echo "[FOUND] $bucket - Status: $status"
fi
done
# If bucket is accessible, look for sensitive files
sensitive_files=(
"backup.sql"
"database.sql"
"dump.sql"
"users.csv"
"credentials.txt"
"config.json"
".env"
"id_rsa"
"private.key"
)
for file in "${sensitive_files[@]}"; do
status=$(curl -s -o /dev/null -w "%{http_code}" "https://bucket.s3.amazonaws.com/$file")
if [ "$status" == "200" ]; then
echo "[CRITICAL] Sensitive file found: $file"
fi
done
| Tool | Description | Usage |
|---|---|---|
| AWS CLI | Official AWS CLI | aws s3 ls s3://bucket |
| S3Scanner | S3 bucket scanner | s3scanner scan --bucket bucket-name |
| AWSBucketDump | Dump S3 buckets | python AWSBucketDump.py -l buckets.txt |
| Bucket Finder | Enumerate buckets | bucket_finder.rb wordlist |
| Tool | Description | Usage |
|---|---|---|
| CloudBrute | Multi-cloud enum | cloudbrute -d target.com |
| cloud_enum | Cloud resource enum | python3 cloud_enum.py -k target |
| Grayhat Warfare | Bucket search | Online service |
| Tool | Description |
|---|---|
| Azure CLI | az storage blob list |
| gsutil | gsutil ls gs://bucket |
| MicroBurst | Azure security toolkit |
#!/bin/bash
TARGET=$1
echo "=== CLOUD STORAGE SCANNER ==="
echo "Target: $TARGET"
echo ""
# Generate bucket name variations
variations=(
"$TARGET"
"${TARGET}-dev"
"${TARGET}-prod"
"${TARGET}-staging"
"${TARGET}-backup"
"${TARGET}-uploads"
"${TARGET}-assets"
"${TARGET}-data"
"${TARGET}-media"
"${TARGET}backup"
"${TARGET}dev"
"${TARGET}prod"
)
# Test AWS S3
echo "[+] Testing AWS S3 buckets..."
for bucket in "${variations[@]}"; do
# Test bucket existence and access
response=$(curl -s -o /dev/null -w "%{http_code}" "https://${bucket}.s3.amazonaws.com")
case $response in
200)
echo " [OPEN] $bucket - Publicly accessible!"
# Try to list
aws s3 ls "s3://${bucket}" --no-sign-request 2>/dev/null | head -5
;;
403)
echo " [EXISTS] $bucket - Access denied (bucket exists)"
;;
404)
# Not found, skip
;;
*)
echo " [?] $bucket - Status: $response"
;;
esac
done
# Test Azure Blob
echo ""
echo "[+] Testing Azure Blob Storage..."
for account in "${variations[@]}"; do
response=$(curl -s -o /dev/null -w "%{http_code}" "https://${account}.blob.core.windows.net/?comp=list")
if [ "$response" != "000" ] && [ "$response" != "404" ]; then
echo " [CHECK] $account.blob.core.windows.net - Status: $response"
fi
done
# Test GCP Storage
echo ""
echo "[+] Testing Google Cloud Storage..."
for bucket in "${variations[@]}"; do
response=$(curl -s -o /dev/null -w "%{http_code}" "https://storage.googleapis.com/${bucket}")
if [ "$response" == "200" ]; then
echo " [OPEN] $bucket - Publicly accessible!"
elif [ "$response" == "403" ]; then
echo " [EXISTS] $bucket - Access denied"
fi
done
echo ""
echo "[+] Scan complete"
# Install
pip install s3scanner
# Scan single bucket
s3scanner scan --bucket bucket-name
# Scan from file
s3scanner scan --buckets-file buckets.txt
# Dump accessible buckets
s3scanner dump --bucket bucket-name --out-dir ./dump/
// Bucket Policy - Deny public access
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "DenyPublicAccess",
"Effect": "Deny",
"Principal": "*",
"Action": "s3:*",
"Resource": ["arn:aws:s3:::bucket-name", "arn:aws:s3:::bucket-name/*"],
"Condition": {
"Bool": {
"aws:SecureTransport": "false"
}
}
}
]
}
# Enable S3 Block Public Access
aws s3api put-public-access-block \
--bucket bucket-name \
--public-access-block-configuration \
"BlockPublicAcls=true,IgnorePublicAcls=true,BlockPublicPolicy=true,RestrictPublicBuckets=true"
# Enable default encryption
aws s3api put-bucket-encryption \
--bucket bucket-name \
--server-side-encryption-configuration \
'{"Rules": [{"ApplyServerSideEncryptionByDefault": {"SSEAlgorithm": "AES256"}}]}'
# Disable public access
az storage account update \
--name accountname \
--resource-group rg \
--allow-blob-public-access false
# Remove public access
gsutil iam ch -d allUsers gs://bucket-name
gsutil iam ch -d allAuthenticatedUsers gs://bucket-name
# Enable uniform bucket-level access
gsutil uniformbucketlevelaccess set on gs://bucket-name
| Finding | CVSS | Severity |
|---|---|---|
| Publicly readable bucket with sensitive data | 9.8 | Critical |
| Publicly writable bucket | 9.8 | Critical |
| Publicly listable bucket | 7.5 | High |
| Bucket exists (enumeration) | 3.7 | Low |
Critical Finding Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
| CWE ID | Title | Description |
|---|---|---|
| CWE-284 | Improper Access Control | Misconfigured bucket ACLs |
| CWE-200 | Information Exposure | Public data disclosure |
| CWE-306 | Missing Authentication | Unauthenticated access |
[ ] Cloud storage URLs identified in application
[ ] AWS S3 buckets tested (read/write/list)
[ ] Azure Blob Storage tested
[ ] Google Cloud Storage tested
[ ] Bucket enumeration performed
[ ] Sensitive files checked
[ ] ACL/permissions reviewed
[ ] Encryption status verified
[ ] Logging enabled
[ ] Public access settings reviewed
[ ] Findings documented