intro to cloud hacking (leaky buckets)

Поділитися
Вставка
  • Опубліковано 30 вер 2024
  • Want to learn more? Make IT (and hacking) your job by learning skills from ITPro: ntck.co/itprotv (30% off FOREVER) *affiliate link
    In this video, you'll learn how to hack the cloud, specifically Amazon S3. We'll cover what S3 buckets are, security basics, how to set up a bucket, how to set up AWS CLI, and how to use AWS Bucket Dump. We'll also explore some common flaws in S3 buckets and how to exploit them, using examples from flaws.cloud. To get started, all you need is a Linux machine (Ubuntu or Kali Linux), and a free AWS account if you want to try some of the more advanced steps.
    Keep in mind that the techniques demonstrated in this video should only be used ethically and with explicit permission. We'll also provide resources for further learning, including the ITPro by ACI Learning Intro to AWS Pentesting course.
    If you're interested in learning more about cloud security and ethical hacking, this video is for you. Don't forget to hit subscribe and turn on notifications for more videos like this!
    Resources mentioned in the video:
    -ITPro by ACI Learning (use code "networkchuck" for 30% off forever): itpro.tv
    -Flaws.cloud: flaws.cloud
    -AWS CLI: docs.aws.amazo...
    -Grayhatwarefare: buckets.grayha...
    -AWS Bucket Dump: github.com/jor...
    -Worst S3 Hacks: businessinsigh...
    🔥🔥Join the NetworkChuck Academy!: ntck.co/NCAcademy
    **Sponsored by ITPro from ACI learning
    SUPPORT NETWORKCHUCK
    ---------------------------------------------------
    ➡️NetworkChuck membership: ntck.co/Premium
    ☕☕ COFFEE and MERCH: ntck.co/coffee
    Check out my new channel: ntck.co/ncclips
    🆘🆘NEED HELP?? Join the Discord Server: / discord
    STUDY WITH ME on Twitch: bit.ly/nc_twitch
    READY TO LEARN??
    ---------------------------------------------------
    -Learn Python: bit.ly/3rzZjzz
    -Get your CCNA: bit.ly/nc-ccna
    FOLLOW ME EVERYWHERE
    ---------------------------------------------------
    Instagram: / networkchuck
    Twitter: / networkchuck
    Facebook: / networkchuck
    Join the Discord server: bit.ly/nc-discord
    AFFILIATES & REFERRALS
    ---------------------------------------------------
    (GEAR I USE...STUFF I RECOMMEND)
    My network gear: geni.us/L6wyIUj
    Amazon Affiliate Store: www.amazon.com...
    Buy a Raspberry Pi: geni.us/aBeqAL
    Do you want to know how I draw on the screen?? Go to ntck.co/EpicPen and use code NetworkChuck to get 20% off!!
    fast and reliable unifi in the cloud: hostifi.com/?v...
    #aws #s3 #kalilinux
  • Наука та технологія

КОМЕНТАРІ • 307

  • @NetworkChuck
    @NetworkChuck  Рік тому +26

    Want to learn more? Make IT (and hacking) your job by learning skills from ITPro: ntck.co/itprotv (30% off FOREVER) *affiliate link
    🔥🔥Join the NetworkChuck Academy!: ntck.co/NCAcademy
    **Sponsored by ITPro from ACI learning

    • @ferdinandw.8952
      @ferdinandw.8952 Рік тому +1

      🄵🄸🅁🅂🅃

    • @GeiPeeruPuutin
      @GeiPeeruPuutin Рік тому

      25 seconds ago huh

    • @6Pain
      @6Pain Рік тому

      Do a playlist about cloud services your awesome ❤

    • @ahmedaribi8572
      @ahmedaribi8572 Рік тому +1

      Hey Network Chuck!! I wish you can make a video to help me make a wifi adapter using a Pi Pico! You know, I can't buy a Wifi Adapter and Pi Pico is so helpful. Thanks in advance! I am a big fan and I can't wait for answer!!

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      Early crew 🤓😅😅🔥💚💚💚💚💚💚💚💚💪🏻🤑😌🤝🥳🥳🥰😈👿🐀.

  • @ismetking2377
    @ismetking2377 Рік тому +106

    *Metaspyclub* is a patriot for telling what he sees on a cheater’s text.

  • @alitentif
    @alitentif Рік тому +105

    Hey *Metaspyclub* what an amazing work this has been and with all the crazy detection that you guys make possible. You guys take hacking to a whole new level and get the job done ASAP!!! I'm wondering what are all your personal qualifications?I don't think that it was ever mentioned before.

  • @yuikagauss
    @yuikagauss Рік тому +47

    Dont open random files from foreign buckets like you did in the end! Some of those buckets are designed to be public!

  • @ArvinUbungen-s1v
    @ArvinUbungen-s1v Рік тому +1

    Legit? Can i try if you are legit? Can you recover my old gmail account? Almost 1month problem .

  • @OhHiNoU
    @OhHiNoU Рік тому +81

    This is epic. Network Chuck never makes a bad video. Keep up the good work.

    • @smith3463
      @smith3463 Рік тому +3

      Yes i agree mr roblox chad face

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      :3 Early crew 🤓😅😅🔥💚💚💚💚💚💚💚💚💪🏻🤑😌🤝🥳🥳🥰😈👿🐀.

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому +1

      Your comment is epic because it has no grammatical errors, unlike the a average comment. It's also the top comment. 😅🥇🤝

    • @ReligionAndMaterialismDebunked
      @ReligionAndMaterialismDebunked Рік тому

      :3 Yesh, I've seen Daniel explain Burp Suite on David Bombal's UA-cam channel before. He's a great teacher! :3

    • @ExpiredMilk420
      @ExpiredMilk420 Рік тому

      Yes, always agree with a fellow Roblox chad face

  • @Memecoinhunters
    @Memecoinhunters Рік тому +4

    Can we hack youtube algo?

  • @Darkweb-s8e
    @Darkweb-s8e Рік тому +2

    hey bro my kali linux tool Osintgram error for private api error please fix 🤣🤣🤣🤣

  • @aagamaperla
    @aagamaperla Рік тому +2

    8 seconds ago? wow

  • @landless-wind
    @landless-wind Рік тому +4

    can you please make a video about manual sql injection from url?

    • @emilne83
      @emilne83 Рік тому +1

      SQL injection is not a complex attack. You just need to understand how sql syntax is interpreted.
      There is a really good xkcd comic that explains it very well. Just google "xkcd explained bobby tables" for a good wiki describing it.
      To protect against it, thr application should "escape" any special characters before using them in SQL statements. This way things like quotes will be treated as part of the text in the variable rather than something that is to be interpreted by the database engine and thus being prone to exploitation.

  • @kiranv185
    @kiranv185 Рік тому +2

    First comment

  • @DeepanshuKumar-pc4lm
    @DeepanshuKumar-pc4lm Рік тому +4

    Hlo you are best hacker of this world

  • @6.mahnoor736
    @6.mahnoor736 Рік тому +1

    Hey bro my Kali Linux tool osintgram error private api please fix my problem. 😂😂😂😂😂

  • @hacking_life
    @hacking_life Рік тому +2

    First?

  • @KiolerAyo
    @KiolerAyo Рік тому +2

    First pin pls

  • @sardorbek_vlogs-w6f
    @sardorbek_vlogs-w6f Рік тому +2

    i'm n1

  • @landless-wind
    @landless-wind Рік тому +1

    can you please make a video about ELB AWS also?
    plsssssssssssss
    plsssssssssssssssssss
    pleasssssssssssssssssssssseeee

  • @xuloIsaias
    @xuloIsaias 11 місяців тому +1

    So in summary, everything is fine if it is not public, also you can use pre-signed url

  • @AjithKumara-v7n
    @AjithKumara-v7n 24 дні тому +1

    Today I learned to make coffee like networkchuck from this video 😁

  • @sardorbek_vlogs-w6f
    @sardorbek_vlogs-w6f Рік тому +2

    haha

  • @Viberthal
    @Viberthal Рік тому +1

    Can you help me fix problem on kali Linux I launched airodump-ng and it not show anything help me out😢

  • @HistoiresdeVie-i5o
    @HistoiresdeVie-i5o Рік тому +1

    how to hide the consumption of a giga that we use at the fiber optic provider

  • @D4kygle
    @D4kygle Рік тому +1

    i dont like coffee ...

  • @azkamustofa1768
    @azkamustofa1768 Рік тому +2

    hola

  • @craigcoffman69
    @craigcoffman69 Рік тому +3

    Hey Chuck 😊

  • @EatonMiddleSinger
    @EatonMiddleSinger Рік тому +11

    Thanks so much for making great hacking videos!

  • @musicaltrack4955
    @musicaltrack4955 Рік тому +1

    I need a hacker whi can havk a website and i will oay him $2000 for my work

  • @ghostkee5031
    @ghostkee5031 Рік тому +1

    bro went to public buckets and says its hacking bruh!

  • @abrarahmad00
    @abrarahmad00 Рік тому +2

    First

  • @GlassThirdEye
    @GlassThirdEye Рік тому +6

    Dont expose your S3 buckets to the internet. Rule of thumb.

    • @Ozymandias1
      @Ozymandias1 Рік тому +1

      Don’t expose important stuff to the internet. I really don’t get why companies would want to put their sensitive data on the cloud. Always assume there is someone who is better at hacking than you are at securing stuff.

  • @xrellikgr
    @xrellikgr Рік тому +1

    I love learning hacking from a non hacker! Thanks for teaching me how to be an unethical hacker! 😈

  • @SergioR00
    @SergioR00 Рік тому +1

    So many bots in these comments unfortunately

  • @severedconnections4821
    @severedconnections4821 Рік тому +2

    You’re a ninja bro

  • @SteamSprint
    @SteamSprint Рік тому +6

    FIRST, Hey network chuck! I have watched your videos for a little while and want to thank you for helping me with all these AMAZING tutorials

  • @Jacob_Jay234
    @Jacob_Jay234 Рік тому +8

    Hi love your content ❤

  • @jijin2450
    @jijin2450 Рік тому +2

    🔥🔥

  • @Rickety3263
    @Rickety3263 Рік тому +3

    I haven’t watched this yet, and I’ll bet that you actually didn’t hack s3. I’ll bet you set up horribly open permissions with horrible access policies and acl’s and then say, “look! I hacked it!”

  • @randomindianguy5022
    @randomindianguy5022 Рік тому +1

    No

  • @meganhowell4795
    @meganhowell4795 Рік тому +16

    As a cloud penetration tester, I can say with confidence that this is the best tutorial I have seen on intro cloud hacking.

    • @NenaDarkPrincess
      @NenaDarkPrincess 7 місяців тому

      Hey! How did you end up becoming a cloud penetration tester? Would be curious to know :)

  • @bayareagolfclub1505
    @bayareagolfclub1505 Рік тому +6

    Hi Chuck, glad to see you're doing well and back to making videos!!! I've been in the industry for quite a few years and stuff like this is sometimes what I need to get excited about tech again and work on my skills. The retrieving of the access key from a past commit was totally cool. I enjoy your enthusiasm and thank you for taking the time to make these videos. Have a good rest of your day! 🙂

  • @wardellcastles
    @wardellcastles 2 місяці тому

    Amazing video.... but thank goodness for 75% speed option on UA-cam!

  • @vishalpandey-gm3mt
    @vishalpandey-gm3mt Рік тому +1

    1st one

  • @DeepanshuKumar-pc4lm
    @DeepanshuKumar-pc4lm Рік тому +6

    Love you sir

  • @sulochanawickramapala3153
    @sulochanawickramapala3153 Рік тому

    Can someone pls make me a youtube vpn or a free software that lets you to access youtube for free without wifi or data (only for youtube) for pc. Plsssss
    Its just that I want it. If you are seeing this pls help me. I am just 13 yrs old
    😥.

  • @Netryon
    @Netryon Рік тому

    You probably know when you already in some homies clan hacking beard you like stuff. Put the corns into this package. I would write to you, but then I have some questions. Why should I be stored in your like chain or will some ninjas come after me hunting me down if they see me in a street.

  • @mhstre6461
    @mhstre6461 Рік тому +1

    1

  • @xelerated
    @xelerated 17 днів тому

    I pay for youtube so i dont get ads, yet here we are. pimping out nonsense for janky vendors

  • @aninsecurecarrot
    @aninsecurecarrot Рік тому +1

    Can I get a

  • @michaeldort6123
    @michaeldort6123 Рік тому

    Hi Cuck, my sincere apologies about the late reply but can you dm me about AI implementation into defense and war strategy

  • @romeoC9968
    @romeoC9968 Рік тому

    did you just say the internet lives on AWS? i expect better from this channel on terminology correctness

  • @thomasembo28
    @thomasembo28 Рік тому

    hey netwerk chuk vraag je kan voor router steken mail scant virussen spam tegenhouden peis veel mensen spam beu zijn soort Latta panden tussen router data controleert dan mail binen krijg door router eigenlijke soort virus scanner router beschermt, zou jij zoo iks kunne uit vinden jij bedrijven en mensen zouden handigen zijn

  • @mcawesomeytyo3312
    @mcawesomeytyo3312 Рік тому

    They will find reference pictures, comics, and drawings. I love to draw

  • @nikusek007
    @nikusek007 Місяць тому

    Hey, shouldn't you wet your filter first before adding coffee?

  • @alldaytherapy2919
    @alldaytherapy2919 Рік тому +1

    I literally typed out that url, worth it.

  • @BongoTermuxHacker
    @BongoTermuxHacker Рік тому +1

    No one knows i hack comment section 😂😂

  • @iamwitchergeraltofrivia9670

    Hahahhhhhaahah no problem windows have visual network for cloud

  • @iamfakechris
    @iamfakechris Рік тому +1

    Epic ❤

  • @ahmadabdallah8471
    @ahmadabdallah8471 Рік тому

    Hi,
    Can a hacker bypass opt if yes make a video of how a hacker can bypass opt.

  • @iyconik1214
    @iyconik1214 Рік тому

    would you make about hacking someone's phones and his file on it?

  • @MarkGrindey
    @MarkGrindey Рік тому

    Amazon S3 is way to expensive like azure.

  • @stickmanland
    @stickmanland Рік тому

    Why is the title lowercase. It's bugging me so much!

  • @iamernestt1
    @iamernestt1 Рік тому

    @NetworkChuck what are your thoughts on pegasus sp*ware

  • @sp3ct3r71
    @sp3ct3r71 Рік тому +1

    First comment

  • @Grinwa
    @Grinwa Рік тому

    Largest cloud service provider also known for the most stupid services names i ever seen

  • @Toastman43
    @Toastman43 9 місяців тому

    How do I download nslookup command cuz I don’t have it

  • @je-t
    @je-t Рік тому

    Hi i need help can anyone help me
    I need Snapchat username checker
    But i have phone

  • @Hessekey
    @Hessekey Рік тому

    Krabby Patty secret formula….😳

  • @cocokretitoletaudo6130
    @cocokretitoletaudo6130 Рік тому

    hay man, got say it, your vids...can say that saved my live, i not a programmer first at alll.... but i'm into a 5yrs of study all strange things happenin in my hacker devices.... and now i need a new content, one that can save me from my bit@#) stalker .......here it goes ..... i need learn rootkit that steal firmmware, inject code to ROM....fake BIOS ....can this really axist ?? hey chuck coffe inst workin, been days awaken ..give me some direction

  • @landless-wind
    @landless-wind Рік тому

    can you please make a video about ELB AWS also?
    plsssssssssssss
    plsssssssssssssssssss
    pleasssssssssssssssssssssseeee

  • @ethantony1225
    @ethantony1225 Рік тому

    I Know why they named it grey hat, cause a black hat is a hacker that steal your information, white hats are GOOD hackers( AKA Ethical hacker) and they also need permission. Grey hats don't need permissions because they are COOL

  • @mateidinescu6155
    @mateidinescu6155 Рік тому

    print("Chuck, I watched all python videos on youtube, and yes I know that there are more, but they are paid, so I was wondering when you will post next video because the last one was 4 months ago. Please we need more python!!!")

  • @BumiAqsa-ul8dp
    @BumiAqsa-ul8dp Рік тому

    Link Hacking slot situs Indonesia??

  • @nazzak2093
    @nazzak2093 Рік тому

    The setting on level 2 is so ridiculous. I can’t see why the AWS came up with this. Where they thinking of AWS family where all companies can access other companies stuff ?

  • @abczwq8364
    @abczwq8364 10 місяців тому

    just found your video, thank you for sharing your knowledge.. I like your videos very much !!! learning a lot from them.

  • @Aman-oy7yc
    @Aman-oy7yc Рік тому

    Can you please clear my doubt that if i useyour link for itprotv, i will get 30% off on subscriptions payment whether monthly or annually?

  • @Man_of_Network
    @Man_of_Network Рік тому

    How to close LAN router fast Ethernet ports?

  • @AlanKlughammer
    @AlanKlughammer Рік тому

    surprised you don't weigh your coffee while pouring. as a coffee geek (as well as an IT hack) I need to weigh the water going into my coffee.

  • @devdave666
    @devdave666 Рік тому +2

    Am I first?

  • @getpapayt8076
    @getpapayt8076 Рік тому +4

    Cheers NetworkMates❤

  • @number0x01
    @number0x01 Рік тому +5

    Fire video as always!

  • @red_hat_007
    @red_hat_007 Рік тому

    とても有益な情報なので
    日本人ですが、チャンネル登録させて頂きました。

  • @masterak4776
    @masterak4776 Рік тому

    Sir help me my Facebook account was hacked someone haw I get back 😢😢😢

  • @Light.--
    @Light.-- Рік тому

    This... is a bucket!
    Dear god-
    There's more!
    No...

  • @aravinth6728
    @aravinth6728 Рік тому

    Can u suggest any reading material ,books regarding hacking ,os and cybersecurity

  • @obsessedtonature.
    @obsessedtonature. Рік тому

    aws s3api put-bucket-lifecycle-configuration --bucket YOUR_BUCKET_NAME --lifecycle-configuration '{
    "Rules": [
    {
    "ID": "RuleToExtendRetention",
    "Status": "Enabled",
    "Prefix": "path/to/object",
    "Transitions": [
    {
    "Days": 365, # New retention period in days
    "StorageClass": "STANDARD_IA" # New storage class after the retention period
    }
    ],
    "Expiration": {
    "Days": 365 # New expiration period in days
    }
    }
    ]
    }'
    Through that can I extend the s3 lifespan?

  • @andreivaduva447
    @andreivaduva447 Рік тому

    can you tell what AWS CLI i should install if i run a kali vm on a macbook air m1?

  • @iamernestt1
    @iamernestt1 Рік тому

    Can you bless us with a pegasus video

  • @TureIMasterEquality
    @TureIMasterEquality 7 місяців тому

    The invisible stairs trick is a classic, keep up the good work...😅

  • @aelaan12
    @aelaan12 Рік тому

    Here is a tip: Do not set up an AWS account at night when people are sleeping in the house. "We are calling you" geez really?

  • @BenjaminFranklin-ep6ge
    @BenjaminFranklin-ep6ge Рік тому

    Still waiting for Alienware to release a laptop with alien technology so advanced hack into anything

  • @WantMoney-k2u
    @WantMoney-k2u Рік тому +5

    Amazing Chuck

  • @justolise
    @justolise Рік тому

    I’m getting into cyber security wanted to ask if getting a mac is a good option ?

  • @TechX1320
    @TechX1320 8 місяців тому

    Subs of mine and I are trying to track down a bucket that we know is public access, but we only have the cloudfront domain forwarder. The game connected to that bucket shutdown in 2017, but for some reason the bucket contents and cdn are active

    • @lilnapkin462
      @lilnapkin462 День тому

      I instantly knew what game you were talking about. Let me know how it goes!

  • @MCHarperYT
    @MCHarperYT Рік тому

    Hey @NetworkChuck, How can you Security the website if someone hacks the site and other things like that like sercuity the ip of people who use the site, or using the site and other things like that @NetworkChuck, I love your content and entertainment at and at 7:02 in the video of **I hacked my wife’s browser (it’s Scary Easy!) and also how can you ban ips if they used to hide the ip, vpns if they bypass a game to get unbanned from other things? Like that?
    Please record a video about it?

  • @BillSingh-u1x
    @BillSingh-u1x Рік тому

    Hey Chuck. Just wanted to reach out. Love your Channel. I'm also in Cyber Security. Been for a while, and I find your channel to be very intriguing. Thank you for all these amazing videos. And yes, let's have some coffee! :)

  • @BurkenProductions
    @BurkenProductions Рік тому

    It's called a slash not a whack! :D

  • @arnesaknussemmtcp5785
    @arnesaknussemmtcp5785 Рік тому

    218 likes in 11 minutes, u can't even look at the whole video 💀

  • @real2late
    @real2late Рік тому

    This is the first hacking video I had fun watching & actually understood everything. Tysm!

  • @AJXD2
    @AJXD2 Рік тому

    man be careful. no one wants you to end up like Enderman

  • @urnewjellyfish
    @urnewjellyfish Рік тому

    You know they would probably find *** *** and ******** **** and helluva boss ****