Identifying Public Resources

Methodology

  • Predictable domains make brute forcing public resources possible.

  • Cloud Enum Tool -

# Github repo
https://github.com/initstring/cloud_enum

# Running the tool
./cloud_enum.py -k somecompany -k somecompany.io -k blockchaindoohickey

List all EC2 IPs

while read r; do
	aws ec2 describe-instances --query=Reservations[].Instances[].PublicIpAddress --region $r | jq -r '.[]' >> ec2-public-ips.txt 
done < regions.txt
sort -u ec2-public-ips.txt -o ec2-public-ips.txt

List all ELB DNS Addresses

List all RDS DNS Addresses


REFERENCES

Last updated

Was this helpful?