
Find leaked secrets via github search
Github Search is a quite powerful and useful feature that can be used to search for sensitive data on repositories. Collection of Github dorks can reveal sensitive personal and/or organizational information such as private keys, credentials, authentication tokens, etc. This list is supposed to be useful for assessing security and performing pen-testing of systems.
github-dork.py is a simple python tool that can search through your repository or your organization/user repositories. It's not a perfect tool at the moment but provides basic functionality to automate the search on your repositories against the dorks specified in the text file.
This tool uses github3.py to talk with GitHub Search API.
Clone this repository and run:
pip install .
You can also run github-dorks using Docker for a consistent environment:
# Build the Docker image
docker build -t github-dorks .
# Run with a GitHub token (recommended)
docker run -e GH_TOKEN=your_github_token github-dorks -u someuser
# Run with username/password
docker run -e GH_USER=your_username -e GH_PWD=your_password github-dorks -u someuser
# Save results to a CSV file
docker run -v $(pwd)/output:/app/output -e GH_TOKEN=your_github_token github-dorks -u someuser -o /app/output/results.csv
GH_USER - Environment variable to specify Github user
GH_PWD - Environment variable to specify a password
GH_TOKEN - Environment variable to specify Github token
GH_URL - Environment variable to specify GitHub Enterprise base URL
Some example usages are listed below:
github-dork.py -r techgaun/github-dorks # search a single repo
github-dork.py -u techgaun # search all repos of a user
github-dork.py -u dev-nepal # search all repos of an organization
GH_USER=techgaun GH_PWD=<mypass> github-dork.py -u dev-nepal # search as authenticated user
GH_TOKEN=<github_token> github-dork.py -u dev-nepal # search using auth token
GH_URL=https://github.example.com github-dork.py -u dev-nepal # search a GitHub Enterprise instance
Please consider contributing dorks that can reveal potentially sensitive information on Github.
I am not categorizing at the moment. Instead, I am going to just the list of dorks with a description. Many of the dorks can be modified to make the search more specific or generic. You can see more options here.