Sandcastle 沙堡



Amazon AWS S3 Bucket Enumeration



What is Amazon S3?

Amazon Simple Storage Service is storage for the Internet. It is designed to make web-scale computing easier for developers.

Amazon S3 has a simple web services interface that you can use to store and retrieve any amount of data, at any time, from anywhere on the web. It gives any developer access to the same highly scalable, reliable, fast, inexpensive data storage infrastructure that Amazon uses to run its own global network of web sites. The service aims to maximize benefits of scale and to pass those benefits on to developers.

Introduction

Sandcastle is Amazon Web Service S3 (AWS S3) Bucket Enumeration Tool. It is original developed by ysx since 2017. Parasimpaticki who forked it and added some new features on it.

Original and forked version of Sandcastle use aws cli tool for the enumeration. However, the aws cli tool has been changed recently and it is no longer working any more. I, Samiux, modified Sandcastle for the purpose.

Sandcastle is developed by Python 2.7.x and it is modified by Samiux. It is released under MIT License.

Download

wget https://www.infosec-ninjas.com/files/sandcastle-1.4.2.tar.gz

sha256sum e64db4546cc005a0594337dd2418689a98642573cccd86ea704ac8617104e465 sandcastle-1.4.2.tar.gz

ChangeLog

Version 1.4.0
Released on AUG 24, 2019 - GMT+8
[+] Modified the code from Parasimpaticki version 1.3

Version 1.4.1
Released on AUG 24, 2019 - GMT+8
[+] Source code clean up

Version 1.4.2 (Latest, Stable)
Released on AUG 25, 2019 - GMT+8
[+] Source code clean up

Usage

tar -xvzf sandcastle-1.4.2.tar.gz
cd sandcastle
./sandcastle -h

./sandcastle -t shopify -b bucket-names.txt