• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 25, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Technology
  • BuckHacker: a search engine that find hackable servers
  • Technology

BuckHacker: a search engine that find hackable servers

Ddos February 20, 2018 3 minutes read
BuckHacker

A new service aimed specifically at white hat hackers has been launched and a project called Buckhacker has created a Google-like search engine that discovers businesses inadvertently by browsing servers exposed to the Internet Leaked sensitive data that allows any user to search for non-secure data stored on Amazon Amazon Web Services (AWS) server buckets.

In fact, there has been a flood of data breaches in the past 2017, with many of the world’s leading companies storing customer and business data on AWS servers without password protection, which means that anyone who knows the exact address of a bucket can associate it Content to visit.

Accenture, WWE, AA, Dow Jones, and even the U.S. National Security Agency have all experienced server configuration errors and were blamed by public opinion for not following the most basic security protocols.

Often, these discoveries require a wide search by publicly available security research groups of publicly accessible servers on the Internet. Buckhacker significantly simplifies this process by allowing users to search AWS lists by using bucket names or file names that may be relevant to the target business. The developers of the project say it is about raising awareness of security rather than helping potential hacker groups.

Although the tool is not designed to be high, it does collect the results and store the information stored in the database for other users to see. Developers in the interview explained that “the goal of this project is to raise awareness of the security buckets, many businesses now suffer due to errors in the management of the bucket. The project is still in its infancy (we are trying to repair one of them some bugs).”

The Buckhacker project was not the first such tool until tools such as AWSBucketDump had allowed users to maliciously find out to expose AWS buckets; Google users could even visit specific server addresses if they knew exactly what to search for. However, Buckhacker is noteworthy because it is probably the easiest-to-use, user-friendly tooling available to date.

Mike Xu Richter, vice president of product management at Bitglass Security, said: “As attackers have easy access to this discovery tool, ensuring that the enterprise infrastructure is not open to the public should be one of the basic principles that must be followed by enterprise IT departments.”

At the same time as the new tool was unveiled, 119,000 U.S. Federal Express customers were also found to have leaked details including home addresses, e-mail addresses, and user’s driver’s license and passport details.

Mr. Richter said the courier company was just another grizzled victim of huge amounts of wealth and deep security but falling into the trap of the same basic but grave mistake.

Amazon pointed out in November 2017 that it will introduce default encryption for all new AWS servers that could theoretically prevent the recurrence of such a leak. However, users need to apply this encryption feature manually to all existing buckets, meaning that data stored on servers unknown to the business is still under serious threat.

Researchers have already realized the existence of this new tool on the Amazon site.

However, in this time,

Sorry guys, we are going offline for maintenance. We went online with the alpha version to early.

— BuckHacker (@thebuckhacker) February 14, 2018

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Only 10% Google users use two-factor authentication
  2. Wine 3.0: Android phone can run Windows apps
  3. Canonical releases security kernel patch for Ubuntu 17.10 & Ubuntu 16.04 LTS (HWE)
  4. Russia Begins Systematic Blocking of Cloudflare, Throttling Internet Access to 16KB
  5. The AI Hectocorn: Anthropic Hits $350B Valuation as Microsoft and NVIDIA Hedge Their Bets
Tags: BuckHacker

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
  • CVE-2026-9454CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects...
  • CVE-2026-9436CVSS 9.8
    A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.