Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Sourcery Starbot ⭐ refactored Explorare/Cloud-Bucket-Leak-Detection-Tools #1

Open
wants to merge 1 commit into
base: main
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 1 addition & 2 deletions core/aliyunOss.py
Original file line number Diff line number Diff line change
Expand Up @@ -101,8 +101,7 @@ def Aliyun_Oss_GetBucketPolicy(self):
"""
try:
result = self.bucket.get_bucket_policy()
policy_json = json.loads(result.policy)
return policy_json
return json.loads(result.policy)
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Function Aliyun_Oss_Bucket_Check.Aliyun_Oss_GetBucketPolicy refactored with the following changes:

except oss2.exceptions.AccessDenied:
return False
except oss2.exceptions.NoSuchBucketPolicy:
Expand Down
31 changes: 16 additions & 15 deletions core/main.py
Original file line number Diff line number Diff line change
Expand Up @@ -36,14 +36,14 @@ def aliyun(target):
aliyun_print_table_header = pt.PrettyTable(
['Bucket', 'BucketHijack', 'GetBucketObjectList', 'PutBucketObject', 'GetBucketAcl', 'PutBucketAcl',
'GetBucketPolicy'])
aliyun_scan_results = {}
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Function aliyun refactored with the following changes:

get_domain = urllib.parse.urlparse(target).netloc
if get_domain == "":
get_target_list = target.split('.')
aliyunOss_Check_init = aliyunOss.Aliyun_Oss_Bucket_Check(target=get_target_list[0],
location=get_target_list[1])
aliyunOss_Exploit_init = aliyunOss.Aliyun_Oss_Bucket_Exploit(target=get_target_list[0],
location=get_target_list[1])
aliyun_scan_results = {}
if aliyunOss_Check_init.Aliyun_Oss_BucketDoesBucketExist():
logger.log("INFOR", f"{target}> 当前存储桶不存在, 尝试劫持存储桶")
if aliyunOss_Exploit_init.Aliyun_Oss_CreateBucket_Exp():
Expand All @@ -53,45 +53,46 @@ def aliyun(target):
aliyunOss_Exploit_init.Aliyun_Oss_PutBucketPolicy_Exp()
aliyunOss_Exploit_init.Aliyun_Oss_GetBucketPolicy_Exp()
aliyunOss_Exploit_init.Aliyun_Oss_PutBucketAcl_Exp()
aliyun_scan_results.update({"BucketDoesBucketExist": "true"})
aliyun_scan_results["BucketDoesBucketExist"] = "true"
else:
aliyun_scan_results.update({"BucketDoesBucketExist": "false"})
aliyun_scan_results["BucketDoesBucketExist"] = "false"
if aliyunOss_Check_init.Aliyun_Oss_GetBucketObject_List():
logger.log("INFOR", f"{target}> 存储桶对象可遍历")
aliyun_scan_results.update({"GetBucketObject": "true"})
aliyun_scan_results["GetBucketObject"] = "true"
else:
logger.log("ALERT", f"{target}> 存储桶对象不可遍历")
aliyun_scan_results.update({"GetBucketObject": "false"})
aliyun_scan_results["GetBucketObject"] = "false"

if aliyunOss_Check_init.Aliyun_Oss_PutBucketObject():
logger.log("INFOR", f"{target}> 可未授权上传对象至存储桶(可导致覆盖已有对象)")
aliyun_scan_results.update({"PutBucketObject": "true"})
aliyun_scan_results["PutBucketObject"] = "true"
else:
logger.log("ALERT", f"{target}> 不可未授权上传对象至存储桶")
aliyun_scan_results.update({"PutBucketObject": "false"})
aliyun_scan_results["PutBucketObject"] = "false"

if aliyunOss_Check_init.Aliyun_Oss_GetBucketAcl():
logger.log("INFOR", f"{target}> 可公开访问存储桶ACL策略")
aliyun_scan_results.update({"GetBucketAcl": "true"})
aliyun_scan_results["GetBucketAcl"] = "true"
else:
logger.log("ALERT", f"{target}> 不可公开访问存储桶ACL策略")
aliyun_scan_results.update({"GetBucketAcl": "false"})
aliyun_scan_results["GetBucketAcl"] = "false"

if aliyunOss_Check_init.Aliyun_Oss_PutBucketAcl():
logger.log("INFOR", f"{target}> 可上传覆盖存储桶ACL策略")
aliyun_scan_results.update({"PutBucketAcl": "true"})
aliyun_scan_results["PutBucketAcl"] = "true"
else:
logger.log("ALERT", f"{target}> 不可上传覆盖存储桶ACL策略")
aliyun_scan_results.update({"PutBucketAcl": "false"})
aliyun_scan_results["PutBucketAcl"] = "false"

results_policy = aliyunOss_Check_init.Aliyun_Oss_GetBucketPolicy()
if results_policy:
if (
results_policy := aliyunOss_Check_init.Aliyun_Oss_GetBucketPolicy()
):
logger.log("INFOR", f"{target}> 可公开获取存储桶Policy策略组")
logger.log("INFOR", f"{target}Policy> {results_policy}")
aliyun_scan_results.update({"GetBucketPolicy": "true"})
aliyun_scan_results["GetBucketPolicy"] = "true"
else:
logger.log("ALERT", f"{target}> 不可公开获取存储桶Policy策略")
aliyun_scan_results.update({"GetBucketPolicy": "false"})
aliyun_scan_results["GetBucketPolicy"] = "false"

aliyun_print_table_header.add_row([target,
aliyun_scan_results['BucketDoesBucketExist'],
Expand Down
2 changes: 1 addition & 1 deletion plugins/results.py
Original file line number Diff line number Diff line change
Expand Up @@ -13,12 +13,12 @@


def aliyun_save_file(target, BucketHijack, GetBucketObjectList, PutBucketObject, GetBucketAcl, PutBucketAcl, GetBucketPolicy):
headers = ['Bucket', 'BucketHijack', 'GetBucketObjectList', 'PutBucketObject', 'GetBucketAcl', 'PutBucketAcl', 'GetBucketPolicy']
filepath = f'{os.getcwd()}/results/{NowTime}.csv'
rows = [
[f"{target}", BucketHijack, GetBucketObjectList, PutBucketObject, GetBucketAcl, PutBucketAcl, GetBucketPolicy]
]
if not os.path.isfile(filepath):
headers = ['Bucket', 'BucketHijack', 'GetBucketObjectList', 'PutBucketObject', 'GetBucketAcl', 'PutBucketAcl', 'GetBucketPolicy']
Comment on lines -16 to +21
Copy link
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Function aliyun_save_file refactored with the following changes:

with open(filepath, 'a+', newline='') as f:
f = csv.writer(f)
f.writerow(headers)
Expand Down