blacklanternsecurity / bbot

A recursive internet scanner for hackers.
https://www.blacklanternsecurity.com/bbot/
GNU General Public License v3.0
4k stars 366 forks source link

Recursive decoding not working for STORAGE_BUCKETs #1518

Open TheTechromancer opened 3 days ago

TheTechromancer commented 3 days ago

We are accidentally excavating hex characters (e.g. 2f) for STORAGE_BUCKETs:

[STORAGE_BUCKET]        {"name": "2fsubstack-post-media", "url": "https://2fsubstack-post-media.s3.amazonaws.com/"} cloud_amazon    (cloud-amazon, cloud-storage-bucket, distance-1)

BBOT command (bbot 2.0):

bbot -f subdomain-enum -m portscan -t blacklanternsecurity.com