
बग बाउंटी प्रोग्राम और पेनिट्रेशन टेस्ट से लीक हुई API कुंजियों को मान्य करने के लिए कमांड का संग्रह, जिसमें AWS, GitHub, Slack और Twilio सहित 80+ सेवाएं शामिल हैं।
KeyHacks विभिन्न API कुंजियों को मान्य करने के तरीके दिखाता है जो किसी Bug Bounty Program या pentest में पाई जाती हैं।
@Gwen001 ने पूरी प्रक्रिया को स्क्रिप्ट किया है जो यहाँ उपलब्ध है और इसे यहाँ पाया जा सकता है।
यदि नीचे दिया गया कमांड missing_text_or_fallback_or_attachments लौटाता है, तो इसका मतलब है कि URL मान्य है, कोई अन्य प्रतिक्रिया इसका मतलब होगी कि URL अमान्य है।```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
## [Slack API टोकन](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
या``` curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
## [SauceLabs उपयोगकर्ता नाम और पहुँच कुंजी](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
नीचे दिए गए URL पर जाकर आप एक्सेस टोकन उत्पन्न कर सकते हैं।``` https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
## Facebook Access Token```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
एक कस्टम टोकन और API कुंजी आवश्यक है।
curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'curl -s -u "user:apikey" https://api.github.com/user curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
## [Github क्लाइंट आईडी और क्लाइंट सीक्रेट](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
संदर्भ: https://abss.me/posts/fcm-takeover``` curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
## GitHub निजी SSH कुंजी