finds.dev← search

// the find

nahamsec/lazys3

★ 638 · Ruby · updated Feb 2024

A single Ruby script that takes a company name, builds permutations of it with prefixes and suffixes from a bundled wordlist, and checks which S3 bucket names exist. It is aimed at security testers doing reconnaissance on targets they are authorised to assess, and at teams checking their own exposure.

Misconfigured buckets often follow predictable naming, such as the company name plus backup, dev, assets or logs, so a short permutation list turns up a useful share of them. The wordlist lives in its own text file, so extending it does not mean touching the Ruby. The whole tool is one script and one wordlist, which makes it quick to read before you run it.

The last push was February 2024 and the changelog stops at 1.0, so there is no sign of upkeep, and the S3 response handling may have drifted since. The README covers only the invocation. It says nothing about what the output looks like or how a public bucket is told apart from a private one, so you have to read the code to find out. The only input is the company name, which makes it awkward to fit into a larger pipeline. Treat a hit as a lead to verify, not as proof of exposed data.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →