vulns.co
/
GKData.io MCP

Cloud object storage

Object storage is its own boundary. Prove the bucket is theirs before you call a public object a finding. A marketing file is not one. Metadata is a later step, and only after a server-side fetch is already shown and the program allows it.

Skill: Cloud object storage

Ask: Is this object store theirs, and has a callback already shown a server-side fetch before any metadata hop?

Stop: You can attribute the store, or you can say the next hop was not allowed. A marketing file is written down as not a finding.

Open the skill

Checklists

  • Cloud / SaaS extras - Public buckets and metadata still pay. Most of the work is proving it is theirs.

Disclosures

No public card yet.

Playbooks

  • Cloud storage and public object hunting - Public buckets still pay, but only after you prove ownership. DNS, TLS SAN, response body, or a billing alias. Guessing a brand name is recon, not a report.
  • Cloud metadata boundary - Metadata is not the first request. It is a later hop, and only after a callback you control has already shown that the server fetches a URL, and only when the program allows that hop.

Tools

  • cloud_enum - Multi-cloud OSINT: public buckets, blobs, and apps named after the target. Confirm ownership before you report.
  • s3scanner - Scans for open S3 buckets (and other cloud storage) and dumps their permissions. Fast cloud misconfig discovery.

Questions

I can list a bucket named after the brand. Is it theirs?

A guessed name is a lead. Ownership is a CNAME, a TLS name, an object that contains their application, or an account id they publish. Without that, do not file it.

Where does cloud metadata go?

On this hunt only after the SSRF brief has a callback you control, and only if the program allows the next hop. Do not start here.

This page is the linked pack hunt_brief("cloud") returns on the MCP connector. Authorized testing only.