daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (5969B)


      1 ---
      2 title: "API Key and Token Leaks"
      3 topic: "API Key Leaks"
      4 topicSlug: "api-key-leaks"
      5 sourcePath: "API Key Leaks/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/API%20Key%20Leaks/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # API Key and Token Leaks
     12 
     13 > API keys and tokens are forms of authentication commonly used to manage permissions and access to both public and private services. Leaking these sensitive pieces of data can lead to unauthorized access, compromised security, and potential data breaches.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Methodology](#methodology)
     19     - [Common Causes of Leaks](#common-causes-of-leaks)
     20     - [Validate The API Key](#validate-the-api-key)
     21 - [Reducing The Attack Surface](#reducing-the-attack-surface)
     22 - [References](#references)
     23 
     24 ## Tools
     25 
     26 - [aquasecurity/trivy](https://github.com/aquasecurity/trivy) - General purpose vulnerability and misconfiguration scanner which also searches for API keys/secrets.
     27 - [blacklanternsecurity/badsecrets](https://github.com/blacklanternsecurity/badsecrets) - A library for detecting known or weak secrets on across many platforms.
     28 - [irsdl/crapsecrets](https://github.com/irsdl/crapsecrets) - A library for detecting known secrets across many web frameworks.
     29 - [d0ge/sign-saboteur](https://github.com/d0ge/sign-saboteur) - SignSaboteur is a Burp Suite extension for editing, signing, verifying various signed web tokens.
     30 - [mazen160/secrets-patterns-db](https://github.com/mazen160/secrets-patterns-db) - Secrets Patterns DB: The largest open-source Database for detecting secrets, API keys, passwords, tokens, and more.
     31 - [momenbasel/KeyFinder](https://github.com/momenbasel/KeyFinder) - is a tool that let you find keys while surfing the web.
     32 - [streaak/keyhacks](https://github.com/streaak/keyhacks) - is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
     33 - [trufflesecurity/truffleHog](https://github.com/trufflesecurity/truffleHog) - Find credentials all over the place.
     34 - [projectdiscovery/nuclei-templates](https://github.com/projectdiscovery/nuclei-templates) - Use these templates to test an API token against many API service endpoints.
     35 
     36     ```powershell
     37     nuclei -t token-spray/ -var token=token_list.txt
     38     ```
     39 
     40 ## Methodology
     41 
     42 - **API Keys**: Unique identifiers used to authenticate requests associated with your project or application.
     43 - **Tokens**: Security tokens (like OAuth tokens) that grant access to protected resources.
     44 
     45 ### Common Causes of Leaks
     46 
     47 - **Hardcoding in Source Code**: Developers may unintentionally leave API keys or tokens directly in the source code.
     48 
     49     ```py
     50     # Example of hardcoded API key
     51     api_key = "1234567890abcdef"
     52     ```
     53 
     54 - **Public Repositories**: Accidentally committing sensitive keys and tokens to publicly accessible version control systems like GitHub.
     55 
     56     ```ps1
     57     ## Scan a Github Organization
     58     docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --org=trufflesecurity
     59     
     60     ## Scan a GitHub Repository, its Issues and Pull Requests
     61     docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest github --repo https://github.com/trufflesecurity/test_keys --issue-comments --pr-comments
     62     ```
     63 
     64 - **Hardcoding in Docker Images**: API keys and credentials might be hardcoded in Docker images hosted on DockerHub or private registries.
     65 
     66     ```ps1
     67     # Scan a Docker image for verified secrets
     68     docker run --rm -it -v "$PWD:/pwd" trufflesecurity/trufflehog:latest docker --image trufflesecurity/secrets
     69     ```
     70 
     71 - **Logs and Debug Information**: Keys and tokens might be inadvertently logged or printed during debugging processes.
     72 
     73 - **Configuration Files**: Including keys and tokens in publicly accessible configuration files (e.g., .env files, config.json, settings.py, or .aws/credentials.).
     74 
     75 ### Validate The API Key
     76 
     77 If assistance is needed in identifying the service that generated the token, [mazen160/secrets-patterns-db](https://github.com/mazen160/secrets-patterns-db) can be consulted. It is the largest open-source database for detecting secrets, API keys, passwords, tokens, and more. This database contains regex patterns for various secrets.
     78 
     79 ```yaml
     80 patterns:
     81   - pattern:
     82       name: AWS API Gateway
     83       regex: '[0-9a-z]+.execute-api.[0-9a-z._-]+.amazonaws.com'
     84       confidence: low
     85   - pattern:
     86       name: AWS API Key
     87       regex: AKIA[0-9A-Z]{16}
     88       confidence: high
     89 ```
     90 
     91 Use [streaak/keyhacks](https://github.com/streaak/keyhacks) or read the documentation of the service to find a quick way to verify the validity of an API key.
     92 
     93 - **Example**: Telegram Bot API Token
     94 
     95     ```ps1
     96     curl https://api.telegram.org/bot<TOKEN>/getMe
     97     ```
     98 
     99 ## Reducing The Attack Surface
    100 
    101 Check the existence of a private key or AWS credentials before committing your changes in a GitHub repository.
    102 
    103 Add these lines to your `.pre-commit-config.yaml` file.
    104 
    105 ```yml
    106 -   repo: https://github.com/pre-commit/pre-commit-hooks
    107     rev: v3.2.0
    108     hooks:
    109     -   id: detect-aws-credentials
    110     -   id: detect-private-key
    111 ```
    112 
    113 ## References
    114 
    115 - [Finding Hidden API Keys & How to Use Them - Sumit Jain - August 24, 2019](https://web.archive.org/web/20191012175520/https://medium.com/@sumitcfe/finding-hidden-api-keys-how-to-use-them-11b1e5d0f01d)
    116 - [Introducing SignSaboteur: Forge Signed Web Tokens with Ease - Zakhar Fedotkin - May 22, 2024](https://web.archive.org/web/20240522172244/https://portswigger.net/research/introducing-signsaboteur-forge-signed-web-tokens-with-ease)
    117 - [Private API Key Leakage Due to Lack of Access Control - yox - August 8, 2018](https://web.archive.org/web/20211208043535/https://hackerone.com/reports/376060)
    118 - [Saying Goodbye to My Favorite 5 Minute P1 - Allyson O'Malley - January 6, 2020](https://web.archive.org/web/20250714230057/https://www.allysonomalley.com/2020/01/06/saying-goodbye-to-my-favorite-5-minute-p1/)