
مجموعة منسقة من الأوامر للتحقق من صحة مفاتيح API المسربة من برامج مكافآت الاختراق واختبارات الاختراق، تغطي أكثر من 80 خدمة بما في ذلك AWS وGitHub وSlack وTwilio.
KeyHacks يعرض طرقًا للتحقق من مفاتيح API المختلفة التي يتم العثور عليها في برنامج Bug Bounty أو اختبار الاختراق.
@Gwen001 قام بكتابة سيناريو العملية بأكملها المتاحة هنا ويمكن العثور عليها هنا
إذا أرجع الأمر التالي missing_text_or_fallback_or_attachments، فهذا يعني أن عنوان URL صالح، وأي ردود أخرى تعني أن عنوان URL غير صالح.```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
## [رمز Slack API](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
أو``` curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
## [اسم المستخدم ومفتاح الوصول لـ SauceLabs](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
يمكنك إنشاء رموز الوصول عن طريق زيارة الرابط أدناه.``` https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
## رمز وصول فيسبوك```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
يتطلب رمزًا مخصصًا ومفتاح API.
curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'curl -s -u "user:apikey" https://api.github.com/user curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
## [معرف عميل GitHub وسر العميل](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
المرجع: https://abss.me/posts/fcm-takeover``` curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
## مفتاح SSH الخاص بـ GitHub