Skip to content

Wordlists resulted from AWS CloudQuarry: Digging for secrets in public AMIs

Notifications You must be signed in to change notification settings

MatJosephs/CloudQuarryWordlists

Repository files navigation

CloudQuarryWordlists

CloudQuarryWordlists is a repository containing files and paths identified in public Amazon Machine Images (AMIs). This was achieved as part of AWS CloudQuarry: Digging for Secrets in Public AMIs, a research project conducted by Eduard Agavriloae and Matei Josephs. This research was presented at DEF CON 32.

Please note that the wordlists are sorted in descending order by frequency. Thus, the filenames towards the beginning of the lists are the most popular, whilst the ones towards the end of the lists are the least popular.

How the wordlists were created

For this research, we ended up scanning the contents of 26,778 public AMIs for secrets. However, for future reference we also kept a record of all files discovered across the scanned AMIs. Our aim behind doing this was to aid future research by showing what types of files and directories are typically found within AMIs.

More details about the research can be found on SecurityCafe.

Saw_your_packet will publish our tooling shortly.

License

MIT

About

Wordlists resulted from AWS CloudQuarry: Digging for secrets in public AMIs

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published