index.md (5969B)
1 --- 2 title: "API Key and Token Leaks" 3 topic: "API Key Leaks" 4 topicSlug: "api-key-leaks" 5 sourcePath: "API Key Leaks/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/API%20Key%20Leaks/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # API Key and Token Leaks 12 13 > API keys and tokens are forms of authentication commonly used to manage permissions and access to both public and private services. Leaking these sensitive pieces of data can lead to unauthorized access, compromised security, and potential data breaches. 14 15 ## Summary 16 17 - [Tools](#tools) 18 - [Methodology](#methodology) 19 - [Common Causes of Leaks](#common-causes-of-leaks) 20 - [Validate The API Key](#validate-the-api-key) 21 - [Reducing The Attack Surface](#reducing-the-attack-surface) 22 - [References](#references) 23 24 ## Tools 25 26 - [aquasecurity/trivy](https://github.com/aquasecurity/trivy) - General purpose vulnerability and misconfiguration scanner which also searches for API keys/secrets. 27 - [blacklanternsecurity/badsecrets](https://github.com/blacklanternsecurity/badsecrets) - A library for detecting known or weak secrets on across many platforms. 28 - [irsdl/crapsecrets](https://github.com/irsdl/crapsecrets) - A library for detecting known secrets across many web frameworks. 29 - [d0ge/sign-saboteur](https://github.com/d0ge/sign-saboteur) - SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens. 30 - [mazen160/secrets-patterns-db](https://github.com/mazen160/secrets-patterns-db) - Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more. 31 - [momenbasel/KeyFinder](https://github.com/momenbasel/KeyFinder) - is a tool that let you find keys while surfing the web. 32 - [streaak/keyhacks](https://github.com/streaak/keyhacks) - is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid. 33 - [trufflesecurity/truffleHog](https://github.com/trufflesecurity/truffleHog) - Find credentials all over the place. 34 - [projectdiscovery/nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) - Use these templates to test an API token against many API service endpoints. 35 36 ```powershell 37 nuclei -t token-spray/ -var token=token_list.txt 38 ``` 39 40 ## Methodology 41 42 - **API Keys**: Unique identifiers used to authenticate requests associated with your project or application. 43 - **Tokens**: Security tokens (like OAuth tokens) that grant access to protected resources. 44 45 ### Common Causes of Leaks 46 47 - **Hardcoding in Source Code**: Developers may unintentionally leave API keys or tokens directly in the source code. 48 49 ```py 50 # Example of hardcoded API key 51 api_key = "1234567890abcdef" 52 ``` 53 54 - **Public Repositories**: Accidentally committing sensitive keys and tokens to publicly accessible version control systems like GitHub. 55 56 ```ps1 57 ## Scan a Github Organization 58 docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity 59 60 ## Scan a GitHub Repository, its Issues and Pull Requests 61 docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys --issue-comments --pr-comments 62 ``` 63 64 - **Hardcoding in Docker Images**: API keys and credentials might be hardcoded in Docker images hosted on DockerHub or private registries. 65 66 ```ps1 67 # Scan a Docker image for verified secrets 68 docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest docker --image trufflesecurity/secrets 69 ``` 70 71 - **Logs and Debug Information**: Keys and tokens might be inadvertently logged or printed during debugging processes. 72 73 - **Configuration Files**: Including keys and tokens in publicly accessible configuration files (e.g., .env files, config.json, settings.py, or .aws/credentials.). 74 75 ### Validate The API Key 76 77 If assistance is needed in identifying the service that generated the token, [mazen160/secrets-patterns-db](https://github.com/mazen160/secrets-patterns-db) can be consulted. It is the largest open-source database for detecting secrets, API keys, passwords, tokens, and more. This database contains regex patterns for various secrets. 78 79 ```yaml 80 patterns: 81 - pattern: 82 name: AWS API Gateway 83 regex: '[0-9a-z]+.execute-api.[0-9a-z._-]+.amazonaws.com' 84 confidence: low 85 - pattern: 86 name: AWS API Key 87 regex: AKIA[0-9A-Z]{16} 88 confidence: high 89 ``` 90 91 Use [streaak/keyhacks](https://github.com/streaak/keyhacks) or read the documentation of the service to find a quick way to verify the validity of an API key. 92 93 - **Example**: Telegram Bot API Token 94 95 ```ps1 96 curl https://api.telegram.org/bot<TOKEN>/getMe 97 ``` 98 99 ## Reducing The Attack Surface 100 101 Check the existence of a private key or AWS credentials before committing your changes in a GitHub repository. 102 103 Add these lines to your `.pre-commit-config.yaml` file. 104 105 ```yml 106 - repo: https://github.com/pre-commit/pre-commit-hooks 107 rev: v3.2.0 108 hooks: 109 - id: detect-aws-credentials 110 - id: detect-private-key 111 ``` 112 113 ## References 114 115 - [Finding Hidden API Keys & How to Use Them - Sumit Jain - August 24, 2019](https://web.archive.org/web/20191012175520/https://medium.com/@sumitcfe/finding-hidden-api-keys-how-to-use-them-11b1e5d0f01d) 116 - [Introducing SignSaboteur: Forge Signed Web Tokens with Ease - Zakhar Fedotkin - May 22, 2024](https://web.archive.org/web/20240522172244/https://portswigger.net/research/introducing-signsaboteur-forge-signed-web-tokens-with-ease) 117 - [Private API Key Leakage Due to Lack of Access Control - yox - August 8, 2018](https://web.archive.org/web/20211208043535/https://hackerone.com/reports/376060) 118 - [Saying Goodbye to My Favorite 5 Minute P1 - Allyson O'Malley - January 6, 2020](https://web.archive.org/web/20250714230057/https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/)