Github Dorks
Github Dorks
Shodan API keys (try other languages too) MLAB Hosted MongoDB Credentials
Slack bot and private tokens Slack services URL often have secret API token as a suffix
WinFrame-Client infos needed by users to connect toCitrix Application Servers Telegram API token
Finding API
Git-Secrets
Gittyleaks Git-All-Secrets
private keys
Trufflehog Gitrob
extension:pem private
GitDorker Github-Dorks
puttygen private keys mongolab credentials in json configs
Git-Hound ShhGit
extension:ppk private extension:json mongolab.com
Repo Security Scanner GitGraber
mysql dump OAuth credentials for accessing Google APIs
Tools
extension:sql mysql dump extension:json googleusercontent client_secret
mysql dump look for password; you can try varieties Redis credentials provided by Redis Labs found in a JSON file
org:Target "S3_ACCESS_KEY_ID" org:Target "aws_secret_key" Redis credentials provided by Redis Labs found in a YAML file try variations, find api keys/secrets
org:Target "S3_ENDPOINT" org:Target "list_aws_accounts" mongolab credentials in yaml configs (try with yml) Contains license keys for Avast! Antivirus
Github Dorks
@hackinarticles
https://github.com/Ignitetechnologies
https://in.linkedin.com/company/hackingarticles
Finding Files
filename:WebServers.xml filename:.bash_history
Created by Jetbrains IDEs, contains webserver credentials with encoded Bash history file
passwords (not encrypted!)
filename:.bash_profile aws
filename:ventrilo_srv.ini
aws access and secret keys
Ventrilo configuration
filename:.cshrc
filename:sshd_config
RC file for csh shell
OpenSSH server config
filename:.dockercfg auth
filename:shadow path:etc
docker registry authentication data
Contains encrypted passwords and account information of new unix systems
filename:.env DB_USERNAME NOT homestead
filename:sftp.json path:.vscode
laravel .env (CI, various ruby based frameworks too)
Created by vscode-sftp for VSCode, contains SFTP/SSH server details and credentails
filename:.env MAIL_HOST=smtp.gmail.com
filename:sftp-config.json
gmail smtp configuration (try different smtp services too)
Created by SFTP for Sublime Text, contains FTP/FTPS or SFTP/SSH server
details and credentials filename:.esmtprc password
filename:settings.py SECRET_KEY esmtp configuration
Django secret keys (usually allows for session hijacking, RCE, etc) filename:.ftpconfig
filename:server.cfg rcon password Created by remote-ssh for Atom, contains SFTP/SSH server details and credentials
Rails master key (used for decrypting credentials.yml.enc for Rails 5.2+) filename:.sh_history
filename:logins.json korn shell history
Firefox saved password collection (key3.db usually in same repo) filename:.tugboat NOT _tugboat
filename:id_rsa or filename:id_dsa Digital Ocean tugboat config
IntelliJ Idea 14 key, try variations for other versions filename:config irc_pass
filename:hub oauth_token possible IRC config