Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
tptacek
on Dec 1, 2017
|
parent
|
context
|
favorite
| on:
Bucket Stream: Finding S3 Buckets by watching cert...
Ignore any direct connection between S3 buckets themselves and particular certificates, and just think of the stream of domain names you get from CT as the seed for a dictionary to grind against S3.
mynewtb
on Dec 1, 2017
[–]
But why do we get those domain names if there (supposedly) is an existing wildcard certificate?
simcop2387
on Dec 1, 2017
|
parent
[–]
To put the s3 bucket under another domain. Such as static.example.com instead of abcdef01123451523245.s3.amazon.com (or whatever it is).
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: