Skip to content
June 21, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Technology
  • BuckHacker: a search engine that find hackable servers
  • Technology

BuckHacker: a search engine that find hackable servers

Do Son February 20, 2018 3 minutes read
BuckHacker
Add as a preferred
source on Google

A new service aimed specifically at white hat hackers has been launched and a project called Buckhacker has created a Google-like search engine that discovers businesses inadvertently by browsing servers exposed to the Internet Leaked sensitive data that allows any user to search for non-secure data stored on Amazon Amazon Web Services (AWS) server buckets.

In fact, there has been a flood of data breaches in the past 2017, with many of the world’s leading companies storing customer and business data on AWS servers without password protection, which means that anyone who knows the exact address of a bucket can associate it Content to visit.

Accenture, WWE, AA, Dow Jones, and even the U.S. National Security Agency have all experienced server configuration errors and were blamed by public opinion for not following the most basic security protocols.

Often, these discoveries require a wide search by publicly available security research groups of publicly accessible servers on the Internet. Buckhacker significantly simplifies this process by allowing users to search AWS lists by using bucket names or file names that may be relevant to the target business. The developers of the project say it is about raising awareness of security rather than helping potential hacker groups.

Although the tool is not designed to be high, it does collect the results and store the information stored in the database for other users to see. Developers in the interview explained that “the goal of this project is to raise awareness of the security buckets, many businesses now suffer due to errors in the management of the bucket. The project is still in its infancy (we are trying to repair one of them some bugs).”

The Buckhacker project was not the first such tool until tools such as AWSBucketDump had allowed users to maliciously find out to expose AWS buckets; Google users could even visit specific server addresses if they knew exactly what to search for. However, Buckhacker is noteworthy because it is probably the easiest-to-use, user-friendly tooling available to date.

Mike Xu Richter, vice president of product management at Bitglass Security, said: “As attackers have easy access to this discovery tool, ensuring that the enterprise infrastructure is not open to the public should be one of the basic principles that must be followed by enterprise IT departments.”

At the same time as the new tool was unveiled, 119,000 U.S. Federal Express customers were also found to have leaked details including home addresses, e-mail addresses, and user’s driver’s license and passport details.

Mr. Richter said the courier company was just another grizzled victim of huge amounts of wealth and deep security but falling into the trap of the same basic but grave mistake.

Amazon pointed out in November 2017 that it will introduce default encryption for all new AWS servers that could theoretically prevent the recurrence of such a leak. However, users need to apply this encryption feature manually to all existing buckets, meaning that data stored on servers unknown to the business is still under serious threat.

Researchers have already realized the existence of this new tool on the Amazon site.

However, in this time,

Sorry guys, we are going offline for maintenance. We went online with the alpha version to early.

— BuckHacker (@thebuckhacker) February 14, 2018

Related coverage

  • Microsoft: AI Now Generates 20-30% of Internal Code
  • The Mac Takeover: Google Gemini’s “Desktop Intelligence” Arrives to Challenge ChatGPT and Claude
  • Microsoft Unveils Enhanced Windows AI Features for “Copilot+ PC”
  • Secure Your Print Jobs: Microsoft Rolls Out Universal Print Anywhere for Everyone
  • Summit supercomputing machine in the U.S has become the fastest supercomputer in the world

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: BuckHacker

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.