Files
nuclei-templates/cloud/enum/gcp-bucket-enum.yaml

40 lines
892 B
YAML
Raw Normal View History

2023-12-07 11:42:31 +05:30
id: gcp-bucket-enum
2023-02-19 13:51:00 +11:00
info:
2023-12-07 11:42:31 +05:30
name: GCP Buckets - Cloud Enumeration
2023-02-19 13:51:00 +11:00
author: initstring
severity: info
2023-12-07 11:42:31 +05:30
description: |
Searches for open and protected buckets in GCP.
metadata:
verified: true
max-request: 1
2024-01-14 14:51:50 +05:30
tags: cloud,enum,cloud-enum,gcp
2023-02-19 13:51:00 +11:00
self-contained: true
variables:
2023-12-07 11:42:31 +05:30
BaseDNS: "storage.googleapis.com"
2023-02-19 13:51:00 +11:00
http:
2023-02-19 13:51:00 +11:00
- raw:
2023-03-09 20:40:04 +05:30
- |
2023-12-07 11:42:31 +05:30
GET http://{{wordlist}}.{{BaseDNS}} HTTP/1.1
Host: {{wordlist}}.{{BaseDNS}}
2023-02-19 13:51:00 +11:00
redirects: false
2023-12-07 11:42:31 +05:30
2023-02-19 13:51:00 +11:00
attack: batteringram
threads: 10
2023-12-07 11:42:31 +05:30
2023-02-19 13:51:00 +11:00
matchers:
- type: status
name: "Open GCP Bucket"
status:
- 200
2023-12-07 11:42:31 +05:30
2023-02-19 13:51:00 +11:00
- type: status
name: "Protected GCP Bucket"
status:
- 403
2024-12-01 13:57:55 +00:00
# digest: 490a0046304402201c96ae60fa7a4b6502e37d1f0a368a06326c5d1c0621e333e1baa733a42b1a4902207412bf98d7e4aaf9b755810b30bda7827b495eae85a5607855376c0a1e1d8ab1:922c64590222798bb761d5b6d8e72950