id: aws-bucket-service info: name: Detect websites using AWS bucket storage author: pdteam severity: info metadata: max-request: 1 tags: aws,tech,bucket http: - method: GET path: - "{{BaseURL}}" matchers-condition: and matchers: - type: dsl dsl: - contains(tolower(header), 'x-amz-bucket') - contains(tolower(header), 'x-amz-request') - contains(tolower(header), 'x-amz-id') - contains(tolower(header), 'amazons3') condition: or - type: dsl dsl: - contains(tolower(header), 'x-guploader-uploadid') negative: true # digest: 4a0a00473045022100f73a2c41da2dc0ac4cb9dd81f1a0637b1124ec077a35301154e14bfc8e582c2202204363b40659aa173eb2bf958820e33aa56563658585a189da5f630a39121e10e2:922c64590222798bb761d5b6d8e72950