Skip to content

Article by Moses Frost (@mosesrenegade).

Hunting GCP Buckets

GCP Buckets are almost 100% identical to AWS S3 Buckets.

Theory: This call is based on OpenStack; maybe most cloud environments will be the same.

Using @digininja's CloudStorageFinder diff the following files:

diff bucket_finder.rb google_finder.rb

The main differences are the URLs:

  • AWS Supports HTTP and HTTPS
  • AWS S3 URLs:, i.e.:
  • GCP Endpoint:

How to find buckets using CloudStorageFinder:

Create a wordlist with any name; in our example, it is wordlist.txt.

$ ruby google_finder.rb wordlist.txt