Skip to content
September 16, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Technology
  • BuckHacker: a search engine that find hackable servers
  • Technology

BuckHacker: a search engine that find hackable servers

Do Son February 20, 2018 3 minutes read
BuckHacker
Add Daily CyberSecurity as a preferred source on Google

A new service aimed specifically at white hat hackers has been launched and a project called Buckhacker has created a Google-like search engine that discovers businesses inadvertently by browsing servers exposed to the Internet Leaked sensitive data that allows any user to search for non-secure data stored on Amazon Amazon Web Services (AWS) server buckets.

In fact, there has been a flood of data breaches in the past 2017, with many of the world’s leading companies storing customer and business data on AWS servers without password protection, which means that anyone who knows the exact address of a bucket can associate it Content to visit.

Accenture, WWE, AA, Dow Jones, and even the U.S. National Security Agency have all experienced server configuration errors and were blamed by public opinion for not following the most basic security protocols.

Often, these discoveries require a wide search by publicly available security research groups of publicly accessible servers on the Internet. Buckhacker significantly simplifies this process by allowing users to search AWS lists by using bucket names or file names that may be relevant to the target business. The developers of the project say it is about raising awareness of security rather than helping potential hacker groups.

Although the tool is not designed to be high, it does collect the results and store the information stored in the database for other users to see. Developers in the interview explained that “the goal of this project is to raise awareness of the security buckets, many businesses now suffer due to errors in the management of the bucket. The project is still in its infancy (we are trying to repair one of them some bugs).”

The Buckhacker project was not the first such tool until tools such as AWSBucketDump had allowed users to maliciously find out to expose AWS buckets; Google users could even visit specific server addresses if they knew exactly what to search for. However, Buckhacker is noteworthy because it is probably the easiest-to-use, user-friendly tooling available to date.

Mike Xu Richter, vice president of product management at Bitglass Security, said: “As attackers have easy access to this discovery tool, ensuring that the enterprise infrastructure is not open to the public should be one of the basic principles that must be followed by enterprise IT departments.”

At the same time as the new tool was unveiled, 119,000 U.S. Federal Express customers were also found to have leaked details including home addresses, e-mail addresses, and user’s driver’s license and passport details.

Mr. Richter said the courier company was just another grizzled victim of huge amounts of wealth and deep security but falling into the trap of the same basic but grave mistake.

Amazon pointed out in November 2017 that it will introduce default encryption for all new AWS servers that could theoretically prevent the recurrence of such a leak. However, users need to apply this encryption feature manually to all existing buckets, meaning that data stored on servers unknown to the business is still under serious threat.

Researchers have already realized the existence of this new tool on the Amazon site.

However, in this time,

Sorry guys, we are going offline for maintenance. We went online with the alpha version to early.

— BuckHacker (@thebuckhacker) February 14, 2018

Related coverage

  • Ubuntu 18.04 LTS will have Boot Speed Boost feature
  • Node.js to Issue CVE for End-of-Life Versions
  • Excel’s New Brain: Agent Mode Brings GPT-5.2 and Claude 4.5 to Desktop
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our tech and OS security coverage helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: BuckHacker

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-87886
    Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin...
    Admin intel📅 Updated: Sep 16, 2026
  • CVE-2026-87827CVSS 10.0
    Certain KGUARD DVR devices running vulnerable firmware expose a system command execution service on all network interfaces without...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to,...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-39364
    Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-27540CVSS 9.0
    Unrestricted Upload of File with Dangerous Type vulnerability in Rymera Web Co Pty Ltd. Woocommerce Wholesale Lead Capture...
    Admin intel📅 Updated: Sep 15, 2026
  • CVE-2026-76461CVSS 9.8
    A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an...
    CISA KEV📅 Added to KEV: Sep 14, 2026
  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-73807CVSS 9.8
    The mySCADA myPRO Manager command API does not properly enforce authentication for...
  • CVE-2026-81855CVSS 9.1
    A hardcoded cryptographic client authentication key vulnerability exists in the robot testing...
  • CVE-2026-78225CVSS 9.0
    A hardcoded cryptographic server key vulnerability exists in the deployer-ng Update Controller...
  • CVE-2026-61560CVSS 9.8
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Prior to version...
  • CVE-2026-73437CVSS 9.6
    On affected platforms running Arista EOS with Dynamic Host Configuration Protocol (DHCP)...
  • CVE-2026-68491CVSS 9.4
    An insufficient check allowed for the overwrite of arbitrary files via a...
  • CVE-2026-61559CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Starting in version...
  • CVE-2026-91939CVSS 9.8
    Cotonti 1.0.0 Comments plugin passes the ci GET parameter to unserialize() without...
  • CVE-2026-61568CVSS 9.6
    `@zereight/mcp-gitlab` is a Model Context Protocol server for GitLab. Versions prior to...
  • CVE-2026-91728CVSS 9.6
    Integer overflow in V8 in Google Chrome prior to 153.0.8010.47 allowed a...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.