superhedgy / AttackSurfaceMapper

AttackSurfaceMapper is a tool that aims to automate the reconnaissance process.
https://AttackSurfaceMapper.com
GNU General Public License v3.0
1.3k stars 192 forks source link

Significant number of false positives in S3 buckets #12

Closed ojensen5115 closed 4 years ago

ojensen5115 commented 5 years ago

I just ran this tool against my own organization's website, and the results are pretty stupefyingly accurate. However, when it comes to S3 buckets, it found the following:

We do not use any S3 buckets, so I would have expected this list to be empty. I have never heard of any of these S3 buckets.

wery67564 commented 5 years ago

I got the same buckets pulled on a different search.

superhedgy commented 4 years ago

@ojensen5115 Indeed there is an issue with the GrayHatWarfare API results. I am looking into it tonight.

ConorDSherman commented 4 years ago

I can confirm what @ojensen5115 is seeing. I am getting almost identical results. Issues appears to still be active

superhedgy commented 4 years ago

Fixed with the latest release. I am also planning to add another option, so you can manually search for keywords.