Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
bucketbuster — Scans public cloud object-storage endpoints across Yandex, VK, Selectel, Sber, Alibaba, Tencent, Huawei, and Baidu to find listable buckets and exposed objects. | Kitploit
Tools/GitHubGitHub/ooafa/bucketbuster
Cloud Infrastructure SecurityOSINT (Open Source Intelligence)ReconnaissanceVulnerability ScannersData ExfiltrationInformation GatheringWeb SecurityPenetration TestingCloud Security
GitHubooafa/bucketbuster

bucketbuster

Scans public cloud object-storage endpoints across Yandex, VK, Selectel, Sber, Alibaba, Tencent, Huawei, and Baidu to find listable buckets and exposed objects.

2124 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
Share

BucketBuster

Cloud object-storage exposure scanner for authorized security testing, bug bounty work, and infrastructure you own.

BucketBuster checks candidate bucket names against public endpoints for Yandex Cloud, VK Cloud, Selectel, SberCloud, Alibaba OSS, Tencent COS, Huawei OBS, and Baidu BOS. It can identify publicly listable buckets, match certificate-related object names, and optionally download publicly accessible objects over HTTP GET.

Authorization required: Use this tool only against assets you own or have explicit permission to test. Scanning or downloading data from third-party buckets may be illegal. You are responsible for complying with applicable laws, contracts, bug-bounty rules, and provider policies.

Features

  • Probes virtual-hosted and path-style endpoints for supported providers.
  • Optional passive DNS resolution before HTTP probing.
  • Parallel scanning with configurable worker count and request delay.
  • Filters by extension, name/path pattern, regular expression, or built-in certificate indicators.
  • Streams findings to JSON and CSV reports.
  • Optionally downloads objects from public listings without credentials.
  • Validates bucket hostnames, supports IDNA/Punycode names, and limits each download to 25 MiB.
  • Blocks private-key containers by default.

Requirements

  • Python 3.9 or newer recommended.
  • Network access to the endpoints being tested.
  • A wordlist containing candidate bucket names, one per line.

Installation

root@kitploit:~
git clone <repository-url> cd bucketbuster python -m venv .venv

Activate the virtual environment:

root@kitploit:~
# Linux/macOS
source .venv/bin/activate

# Windows PowerShell
.\.venv\Scripts\Activate.ps1

Install dependencies:

root@kitploit:~
python -m pip install -r requirements.txt

Quick Start

Create a wordlist such as buckets.txt:

root@kitploit:~
example-company
example-company-backup
example-company-documents

Run the default provider set, Yandex Cloud and VK Cloud:

root@kitploit:~
python bucketbuster.py --wordlist buckets.txt

The scanner reports HTTP 200 responses, public listings, matching object names, and access-denied endpoints that appear to exist. A 404 response is ignored.

Provider Coverage

Provider flagServiceIncluded endpoint families
yandexYandex CloudStorage and website endpoints
vkVK Cloudvkcloud-storage.ru endpoints
selectelSelectelS3 and selstorage.ru endpoints
sberSberCloudOBS and s3.cloud.ru endpoints
aliyunAlibaba Cloud OSSSelected China regions
tencentTencent Cloud COSSelected China and Asia regions
huaweiHuawei Cloud OBSSelected China regions
baiduBaidu Cloud BOSSelected China and Asia regions

Provider groups:

root@kitploit:~
--providers russia   # yandex, vk, selectel, sber
--providers china    # aliyun, tencent, huawei, baidu
--providers all      # every supported provider

You can also provide a comma-separated list, for example:

root@kitploit:~
python bucketbuster.py -w buckets.txt --providers aliyun,tencent

Command-Line Options

Input and probing

OptionDefaultDescription
-w, --wordlist PATHRequiredFile containing candidate bucket names, one per line. Blank lines and comments beginning with # are ignored.
--providers VALUEyandex,vkComma-separated provider flags, or all, russia, or china.
--dnsDisabledPerform a passive DNS check and skip hostnames that do not resolve.
-t, --threads N12Number of concurrent bucket workers.
--delay SECONDS0.12Delay between HTTP requests.

Matching and filtering

OptionDescription
--match-ext LISTComma-separated extensions such as .pfx,.p12,.cer,.crt. A leading dot is added when omitted.
--match-name LISTComma-separated case-insensitive name/path substrings. A simple * wildcard is supported.
--match-regex PATTERNCase-insensitive regular expression matched against the full object key. Pass the option multiple times for multiple patterns.
--match-certEnable the built-in certificate extensions and keywords, including CryptoPro, GOST, signing, certificate, and Russian certificate terms.

When one or more filters are supplied, they use OR logic: an object matches if it satisfies any configured extension, name, regex, or --match-cert condition. With no filters, every listed object is considered a match for reporting and download selection.

Reports

OptionDescription
-o, --output PATHWrite a JSON report. Results are streamed during scanning.
--csv PATHWrite a CSV report. Results are streamed during scanning.

Downloads

OptionDefaultDescription
--downloadDisabledDownload matching objects from public listings using unauthenticated HTTP GET requests.
--download-allDisabledWith --download, attempt every object in each parsed public listing and ignore matching filters.
--download-dir PATH./downloadsRoot directory for downloaded objects.
--allow-private-keysDisabledPermit downloads of .pfx, .p12, .key, .p8, and .pem objects. Use only when explicitly authorized.

--download-all requires --download. Downloads are limited to 25 MiB per object, and empty responses or non-200 responses are not saved. Private-key containers are blocked unless --allow-private-keys is explicitly supplied.

Examples

Scan Russia/CIS providers with passive DNS checks:

root@kitploit:~
python bucketbuster.py -w buckets.txt --providers russia --dns

Scan all supported providers and write both report formats:

root@kitploit:~
python bucketbuster.py \
	--wordlist buckets.txt \
	--providers all \
	--dns \
	--output findings.json \
	--csv findings.csv

Report likely certificate files by extension:

root@kitploit:~
python bucketbuster.py -w buckets.txt --match-ext .pfx,.p12,.cer,.crt,.der

Match names and paths using substrings and simple wildcards:

root@kitploit:~
python bucketbuster.py \
	-w buckets.txt \
	--match-name cryptopro,*keystore*,backups/*.sql

Use multiple regular expressions:

root@kitploit:~
python bucketbuster.py \
	-w buckets.txt \
	--match-regex '.*backup.*\.sql$' \
	--match-regex 'config/.*\.ya?ml$'

Enable the built-in certificate-related extension and keyword list:

root@kitploit:~
python bucketbuster.py -w buckets.txt --match-cert

Download only objects matching selected extensions:

root@kitploit:~
python bucketbuster.py \
	-w buckets.txt \
	--providers aliyun,tencent \
	--match-ext .cer,.crt,.p7b \
	--download \
	--download-dir ./authorized-downloads

Download every object visible in a public listing. This intentionally ignores all matching filters and should be used only on an approved test asset:

root@kitploit:~
python bucketbuster.py -w buckets.txt --download --download-all

Input and Output

Candidate input may be a bare bucket name, hostname, full storage URL, or path-style URL. Names are normalized and validated before any DNS or HTTP operation. Duplicate and invalid candidates are discarded.

JSON findings include provider, bucket, URL, HTTP status, listability, matched files, all files discovered in a listing, DNS state, notes, a short listing snippet, and downloaded local paths. CSV contains the main finding fields; file lists are serialized as semicolon-separated values.

Downloads are organized below the selected directory by provider and bucket:

root@kitploit:~
downloads/
	yandex/
		example-company/
			certificates/client.cer

Object paths are sanitized before being written locally. Downloading is sequential and rate-limited by the configured delay.

Safety and Responsible Use

  • This tool does not authenticate to cloud providers or bypass access controls.
  • Public listing and object access may still expose sensitive information; treat findings as confidential and follow the authorization scope.
  • The default scan can make requests to many provider endpoints. Set a conservative --threads value and increase --delay when required by a program or provider policy.
  • Do not use --download, --download-all, or --allow-private-keys unless the authorization explicitly covers the relevant objects and data handling.
  • Stop testing and notify the asset owner according to the applicable disclosure process when sensitive material is found.

License

BucketBuster is released under the BSD 2-Clause License.

Download Tool