Logo

dev-resources.site

for different kinds of informations.

Unveiling the Unseen: A Journey from Simple Recon Using Shodan to Leaking AWS Secrets

Published at
12/11/2024
Categories
writing
security
cybersecurity
Author
tecno-security
Categories
3 categories in total
writing
open
security
open
cybersecurity
open
Author
14 person written this
tecno-security
open
Unveiling the Unseen: A Journey from Simple Recon Using Shodan to Leaking AWS Secrets

The world of bug bounty hunting is filled with thrilling moments when some simple recon techniques lead to a major vulnerability discovery. Omar Sha Rafi from Bangladesh shares with us the process of discovering and exploiting multiple vulnerabilities in a popular music streaming platform. Due to the confidentiality of the program, all sensitive details such as domain names, IP addresses, and credentials have been redacted.

Summary:

● Found an exposed IP via Shodan and identified open ports using Naabu, leading to further investigation.

● Discovered admin email leakage and internal app details through brute forcing directories.

● Downloaded and Decompiled an APK that uncovered hardcoded AWS credentials, enabling unauthorized access to S3 buckets.

  • Part 1: The Starting Point – Shodan Search and Discovering the Origin IP
  • Part 2: Full Port Scanning with Naabu
  • Part 3: Directory Brute forcing with Ffuf
  • Part 4: Leaking PII – The Users Endpoint
  • Part 5: Exposing Development Information – The Apps Endpoint
  • Part 6: Decompiling the APK and Finding Exposed AWS Keys
  • Part 7: Using AWS CLI to Access S3 Buckets
  • Part 8: Root Cause of the Vulnerability
  • Part 9: Protection Measures for AWS Keys

User activity: Follow @TecnoSRC and like this post, we will randomly select 10 users to give away 10 security credits!

writing Article's
30 articles in total
Favicon
Well, it finally happened—my first <25 reads in 24 hours. 🎉 Lesson learned: not every post will be a hit, and that’s okay! 🚀 Writing is about growth, engagement, and experimenting. Thanks for being part of the journey—check it out @dansasser! #AIWorkflow
Favicon
I Earned a $95 Bonus from the Medium Partner Program
Favicon
How to Use Powerdrill AI to Make a Literary Analysis
Favicon
Software Testing Tasks with Challenges, Tools, and Best Practices
Favicon
My Technical Writing Framework
Favicon
Automated Penetration Testing: A Guide to Domain Collection
Favicon
UX Writing Challenge: Day 1
Favicon
Oh, and before I get carried away—Hi! I am mary😁, a software engineer with a passion for crafting beautiful designs and websites. Lately, I have started writing on dev.to weekly, sharing my experiences while soaking up wisdom from this amazing community.
Favicon
Storia's First Tales: Three Worlds Awaiting Your Ideas
Favicon
How I Set Up My Custom Domain and Email for Substack
Favicon
How I wrote this technical post with Nebo: an Android gamechanger ✍️
Favicon
Crear software: Juego de personas
Favicon
Storia: Where Community Chaos Meets AI Storytelling
Favicon
Guidelines about the Refer-a-Friend Program
Favicon
Looking for an Editor? I'm Offering Free Editing This Weekend and Next Week! If you’re working on an article and need an editor, I’d be happy to help out for free this weekend and sometime next week. Just shoot me a message on X https://x.com/notesbyeze
Favicon
La dualidad de tu profesión.
Favicon
I'm Answering the Blog Questions Challenge — Dev.to Edition
Favicon
Aspiring Tech Writer Looking to Collaborate with Developers!
Favicon
Data Analytics Skills for Technical Writers
Favicon
SQL Injection Principles, Vulnerability Discovery and Mitigation Strategies
Favicon
Building CrossPost: A Publishing Tool for Technical Writers
Favicon
Who's hiring (January 2025)
Favicon
Why You Should Enroll in a Leading Interior Design Institute
Favicon
AWS Community: How User Groups Transformed My Cloud Career
Favicon
Year in Review - 2024 Edition
Favicon
Unveiling the Unseen: A Journey from Simple Recon Using Shodan to Leaking AWS Secrets
Favicon
Timeless Elegance: Classic Interior Design Styles That Never Go Out of Fashion
Favicon
How do kraft paper window boxes better the product presentation?
Favicon
Trinka AI
Favicon
Understanding User Needs in Technical Writing: How Frameworks Like Diátaxis Help

Featured ones: