
AWS AMAZON S3 Bucket Takeover Scanner & Claim Tool
S3 Bucket Takeover Scanner & Claim Tool

S3 Bucket Takeover Scanner & Claim Tool is a Python 2.7-based utility that:
This tool is ideal for bug bounty hunting, cloud asset auditing, or legal penetration testing within authorized environments.
The specified bucket does not exist responseindex.html file to the bucket and enable static hostingvulnerable_buckets.txt| Function | Purpose |
|---|---|
run_scan() | Checks if the target domain points to a non-existent S3 bucket |
lookup_cname() | Resolves CNAME to identify AWS-hosted targets |
extract_region_from_cname() | Extracts AWS region info for bucket creation |
takeover_bucket() | Automatically creates & configures a claimed bucket |
scan_domain() | Attempts HTTPS and HTTP scanning |
main() | Reads domain list and starts threaded scanning |
boto3, requests librariesdig (Linux-based DNS utility)domains.txt containing a list of target domains:example1.com example2.com
python2 script.py domains.txt
vulnerable_buckets.txt🟥 IMPORTANT: This tool must only be used for:
Unauthorized use of this tool for exploitation or data manipulation is illegal and may result in criminal prosecution under international cybersecurity laws.
Another Disclaimer:
I have written the disclaimer on the cover of Jenderal92. You can check it HERE !!!