
バグバウンティプログラムやペネトレーションテストで流出したAPIキーを検証するためのコマンドの厳選されたコレクション。AWS、GitHub、Slack、Twilioを含む80以上のサービスをカバーしています。
<p align="center">
<img src="https://assets.kitploit.com/production/public/readmes/4653/0b5b34d5398000ecc5e0743d278876caf96f87191f91a06860c706905996a642.png" width="300px">
</p>
</br>
KeyHacksは、バグバウンティプログラムやペンテストで見つけたさまざまなAPIキーを検証する方法を示しています。
@Gwen001 が全プロセスをスクリプト化しており、こちらから入手できます。[こちら](https://github.com/gwen001/pentest-tools/blob/master/keyhacks.sh)
# 目次
- [ABTasty API Key](#ABTasty-API-Key)
- [Algolia API key](#Algolia-API-key)
- [Amplitude API Keys](#Amplitude-API-Keys)
- [Asana Access token](#Asana-Access-Token)
- [AWS Access Key ID and Secret](#AWS-Access-Key-ID-and-Secret)
- [Azure Application Insights APP ID and API Key](#Azure-Application-Insights-APP-ID-and-API-Key)
- [Bazaarvoice Passkey](#Bazaarvoice-Passkey)
- [Bing Maps API Key](#Bing-Maps-API-Key)
- [Bit.ly Access token](#Bitly-Access-token)
- [Branch.io Key and Secret](#BranchIO-Key-and-Secret)
- [BrowserStack Access Key](#BrowserStack-Access-Key)
- [Buildkite Access token](#Buildkite-Access-token)
- [ButterCMS API Key](#ButterCMS-API-Key)
- [Calendly API Key](#Calendly-API-Key)
- [Contentful Access Token](#Contentful-access-token)
- [CircleCI Access Token](#CircleCI-Access-Token)
- [Cloudflare API key](#cloudflare-api-key)
- [Cypress record key](#Cypress-record-key)
- [DataDog API key](#DataDog-API-key)
- [Delighted API key](#Delighted-api-key)
- [Deviant Art Access Token](#Deviant-Art-Access-Token)
- [Deviant Art Secret](#Deviant-Art-Secret)
- [Dropbox API](#Dropbox-API)
- [Facebook Access Token](#Facebook-Access-Token)
- [Facebook AppSecret](#Facebook-AppSecret)
- [Firebase](#Firebase)
- [Firebase Cloud Messaging (FCM)](#Firebase-Cloud-Messaging)
- [FreshDesk API Key](#FreshDesk-API-key)
- [Github client id and client secret](#Github-client-id-and-client-secret)
- [GitHub private SSH key](#GitHub-private-SSH-key)
- [Github Token](#Github-Token)
- [Gitlab personal access token](#Gitlab-personal-access-token)
- [GitLab runner registration token](#Gitlab-runner-registration-token)
- [Google Cloud Service Account credentials](#Google-Cloud-Service-Account-credentials)
- [Google Maps API key](#Google-Maps-API-key)
- [Google Recaptcha key](#Google-Recaptcha-key)
- [Grafana Access Token](#Grafana-Access-Token)
- [Help Scout OAUTH](#Help-Scout-OAUTH)
- [Heroku API key](#Heroku-API-key)
- [HubSpot API key](#Hubspot-API-key)
- [Infura API key](#Infura-API-key)
- [Instagram Access Token](#Instagram-Access-Token)
- [Instagram Basic Display API](#Instagram-Basic-Display-API-Access-Token)
- [Instagram Graph API](#Instagram-Graph-Api-Access-Token)
- [Ipstack API Key](#Ipstack-API-Key)
- [Iterable API Key](#Iterable-API-Key)
- [JumpCloud API Key](#JumpCloud-API-Key)
- [Keen.io API Key](#Keenio-API-Key)
- [LinkedIn OAUTH](#LinkedIn-OAUTH)
- [Lokalise API Key](#Lokalise-API-Key)
- [Loqate API Key](#Loqate-API-key)
- [MailChimp API Key](#MailChimp-API-Key)
- [MailGun Private Key](#MailGun-Private-Key)
- [Mapbox API key](#Mapbox-API-Key)
- [Microsoft Azure Tenant](#Microsoft-Azure-Tenant)
- [Microsoft Shared Access Signatures (SAS)](#Microsoft-Shared-Access-Signatures-(SAS))
- [Microsoft Teams Webhook](#Microsoft-Teams-Webhook)
- [New Relic Personal API Key (NerdGraph)](#New-Relic-Personal-API-Key-(NerdGraph))
- [New Relic REST API](#New-Relic-REST-API)
- [NPM token](#NPM-token)
- [OpsGenie API Key](#OpsGenie-API-Key)
- [Pagerduty API token](#Pagerduty-API-token)
- [Paypal client id and secret key](#Paypal-client-id-and-secret-key)
- [Pendo Integration Key](#Pendo-Integration-Key)
- [PivotalTracker API Token](#PivotalTracker-API-Token)
- [Razorpay API key and secret key](#Razorpay-keys)
- [Salesforce API key](#Salesforce-API-key)
- [SauceLabs Username and access Key](#SauceLabs-Username-and-access-Key)
- [SendGrid API Token](#SendGrid-API-Token)
- [Shodan.io](#Shodan-Api-Key)
- [Slack API token](#Slack-API-token)
- [Slack Webhook](#Slack-Webhook)
- [Sonarcloud](#Sonarcloud-Token)
- [Spotify Access Token](#Spotify-Access-Token)
- [Square](#Square)
- [Stripe Live Token](#Stripe-Live-Token)
- [Telegram Bot API Token](#Telegram-Bot-API-Token)
- [Travis CI API token](#Travis-CI-API-token)
- [Twilio Account_sid and Auth token](#Twilio-Account_sid-and-Auth-token)
- [Twitter API Secret](#Twitter-API-Secret)
- [Twitter Bearer token](#Twitter-Bearer-token)
- [Visual Studio App Center API Token](#Visual-Studio-App-Center-API-Token)
- [WakaTime API Key](#WakaTime-API-Key)
- [WeGlot Api Key](#weglot-api-key)
- [WPEngine API Key](#WPEngine-API-Key)
- [YouTube API Key](#YouTube-API-Key)
- [Zapier Webhook Token](#Zapier-Webhook-Token)
- [Zendesk Access token](#Zendesk-Access-Token)
- [Zendesk API key](#Zendesk-api-key)
# 詳細情報
## [Slack Webhook](https://api.slack.com/incoming-webhooks)
以下のコマンドが`missing_text_or_fallback_or_attachments`を返した場合、URLは有効です。その他の応答はURLが無効であることを意味します。```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
```
## [Slack API トークン](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
```
または```
curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
```
## [SauceLabs ユーザー名とアクセスキー](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
```
## Facebook AppSecret
以下のURLにアクセスしてアクセストークンを生成できます。```
https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
```
## Facebook アクセストークン```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
```
## [Firebase](https://firebase.google.com/)
**カスタムトークン**と**APIキー**が必要です。
1. IDトークンとリフレッシュトークンをカスタムトークンとAPIキーから取得: `curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'`
2. IDトークンを認証トークンと交換: `curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'`
## [Github Token](https://developer.github.com/v3/)```
curl -s -u "user:apikey" https://api.github.com/user
curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
# Check scope of your api token
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
```
## [GithubクライアントIDとクライアントシークレット](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
```
## [Firebase Cloud Messaging](https://firebase.google.com/docs/cloud-messaging)
参照: https://abss.me/posts/fcm-takeover```
curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
```
## GitHub private SSH key
SSH秘密鍵はgithub.comに対してテストし、既存のユーザーアカウントに登録されているかどうかを確認できます。キーが存在する場合、そのキーに対応するユーザー名が提供されます。([ソース](https://github.com/streaak/keyhacks/issues/2))```
$ ssh -i <path to SSH private key> -T [email protected]
Hi <username>! You've successfully authenticated, but GitHub does not provide shell access.
```
## [Twilio Account_sid と Auth token](https://www.twilio.com/docs/iam/api/account)```
curl -X GET 'https://api.twilio.com/2010-04-01/Accounts.json' -u ACCOUNT_SID:AUTH_TOKEN
```
## [Twitter API Secret](https://developer.twitter.com/en/docs/basics/authentication/guides/bearer-tokens.html)```
curl -u 'API key:API secret key' --data 'grant_type=client_credentials' 'https://api.twitter.com/oauth2/token'
```
## [Twitter ベアラートークン](https://developer.twitter.com/en/docs/accounts-and-users/subscribe-account-activity/api-reference/aaa-premium)```
curl --request GET --url https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json --header 'authorization: Bearer TOKEN'
```
## [HubSpot API キー](https://developers.hubspot.com/docs/methods/owners/get_owners)
すべてのオーナーを取得する:```
https://api.hubapi.com/owners/v2/owners?hapikey={keyhere}
```
すべての連絡先詳細を取得:```
https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={keyhere}
```
## [Infura APIキー](https://docs.infura.io/infura/networks/ethereum/how-to/secure-a-project/project-id)```
curl https://mainnet.infura.io/v3/<YOUR-API-KEY> -X POST -H "Content-Type: application/json" -d '{"jsonrpc":"2.0","method":"eth_accounts","params":[],"id":1}'
```
## [Deviant Art シークレット](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/oauth2/token -d grant_type=client_credentials -d client_id=ID_HERE -d client_secret=mysecret
```
## [Deviant Art アクセストークン](https://www.deviantart.com/developers/authentication)```
curl https://www.deviantart.com/api/v1/oauth2/placebo -d access_token=Alph4num3r1ct0k3nv4lu3
```
## [Pendo 統合キー](https://help.pendo.io/resources/support-library/api/index.html?bash#authentication)```
curl -X GET https://app.pendo.io/api/v1/feature -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
curl -X GET https://app.pendo.io/api/v1/metadata/schema/account -H 'content-type: application/json' -H 'x-pendo-integration-key:KEY_HERE'
```
## [SendGrid API Token](https://docs.sendgrid.com/api-reference)```
curl -X "GET" "https://api.sendgrid.com/v3/scopes" -H "Authorization: Bearer SENDGRID_TOKEN-HERE" -H "Content-Type: application/json"
```
## [Square](https://squareup.com/)
**検出:**
アプリID/クライアントシークレット: `sq0[a-z]{3}-[0-9A-Za-z\-_]{22,43}`
認証トークン: `EAAA[a-zA-Z0-9]{60}`
**テスト用アプリID & クライアントシークレット:**```
curl "https://squareup.com/oauth2/revoke" -d '{"access_token":"[RANDOM_STRING]","client_id":"[APP_ID]"}' -H "Content-Type: application/json" -H "Authorization: Client [CLIENT_SECRET]"
```
有効な認証情報を示す応答:```
empty
```
無効な資格情報を示す応答:```
{
"message": "Not Authorized",
"type": "service.not_authorized"
}
```
**テスト認証トークン:**```
curl https://connect.squareup.com/v2/locations -H "Authorization: Bearer [AUHT_TOKEN]"
```
有効な認証情報を示す応答:```
{"locations":[{"id":"CBASELqoYPXr7RtT-9BRMlxGpfcgAQ","name":"Coffee \u0026 Toffee SF","address":{"address_line_1":"1455 Market Street","locality":"San Francisco","administrative_district_level_1":"CA","postal_code":"94103","country":"US"},"timezone":"America/Los_Angeles"........
```
不正な資格情報を示す応答:```
{"errors":[{"category":"AUTHENTICATION_ERROR","code":"UNAUTHORIZED","detail":"This request could not be authorized."}]}
```
## [Contentful Access Token](https://www.contentful.com/developers/docs/references/authentication)```
curl -v https://cdn.contentful.com/spaces/SPACE_ID_HERE/entries\?access_token\=ACCESS_TOKEN_HERE
```
## [Dropbox API](https://www.dropbox.com/developers/documentation/http/documentation)```
curl -X POST https://api.dropboxapi.com/2/users/get_current_account --header "Authorization: Bearer TOKEN_HERE"
```
## [AWS Access Key ID and Secret](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html)
[awscli](https://aws.amazon.com/cli/) をインストールし、[access key and secret to environment variables](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html) を設定し、以下のコマンドを実行します:```
AWS_ACCESS_KEY_ID=xxxx AWS_SECRET_ACCESS_KEY=yyyy aws sts get-caller-identity
```
AWSクレデンシャルの権限は、[Enumerate-IAM](https://github.com/andresriancho/enumerate-iam)を使用して決定できます。
これにより、S3バケットのチェックだけではなく、発見されたAWSクレデンシャルの権限のより広いビューが得られます。```
git clone https://github.com/andresriancho/enumerate-iam
cd enumerate-iam
./enumerate-iam.py --access-key AKIA... --secret-key StF0q...
```
## [Lokalise APIキー](https://app.lokalise.com/api2docs/curl/#resource-authentication)```curl --request GET \
--url https://api.lokalise.com/api2/projects/ \
--header 'x-api-token: [API-KEY-HERE]'
```
## [MailGun 秘密鍵](https://documentation.mailgun.com/en/latest/api_reference.html)```
curl --user 'api:YOUR_API_KEY' "https://api.mailgun.net/v3/domains"
```
## [FreshDesk API キー](https://developers.freshdesk.com/api/#getting-started)```
curl -v -u [email protected]:test -X GET 'https://domain.freshdesk.com/api/v2/groups/1'
This requires the API key in '[email protected]', pass in 'test' and 'domain.freshdesk.com' to be the instance url of the target. In case you get a 403, try the endpoint api/v2/tickets, which is accessible for all keys.
```
## [JumpCloud API キー](https://docs.jumpcloud.com/1.0/authentication-and-authorization/authentication-and-authorization-overview)
#### [v1](https://docs.jumpcloud.com/1.0/systemusers)```
List systems:
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systems"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/systemusers"
curl -H "x-api-key: APIKEYHERE" "https://console.jumpcloud.com/api/applications"
```
#### [v2](https://docs.jumpcloud.com/2.0/systems/list-the-associations-of-a-system)```
List systems:
curl -X GET https://console.jumpcloud.com/api/v2/systems/{System_ID}/memberof \
-H 'Accept: application/json' \
-H 'Content-Type: application/json' \
-H 'x-api-key: {API_KEY}'
```
## Microsoft Azure テナント
形式:```
CLIENT_ID: [0-9a-z\-]{36}
CLIENT_SECRET: [0-9A-Za-z\+\=]{40,50}
TENANT_ID: [0-9a-z\-]{36}
```
検証:```
curl -X POST -H "Content-Type: application/x-www-form-urlencoded" -d 'client_id=<CLIENT_ID>&scope=https%3A%2F%2Fgraph.microsoft.com%2F.default&client_secret=<CLIENT_SECRET>&grant_type=client_credentials' 'https://login.microsoftonline.com/<TENANT_ID>/oauth2/v2.0/token'
```
## [Microsoft Shared Access Signatures (SAS)](https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/storage/common/storage-dotnet-shared-access-signature-part-1.md)
以下のPowerShellを使用して、Shared Access Signature Tokenをテストできます。```powershell
static void UseAccountSAS(string sasToken)
{
// Create new storage credentials using the SAS token.
StorageCredentials accountSAS = new StorageCredentials(sasToken);
// Use these credentials and the account name to create a Blob service client.
CloudStorageAccount accountWithSAS = new CloudStorageAccount(accountSAS, "account-name", endpointSuffix: null, useHttps: true);
CloudBlobClient blobClientWithSAS = accountWithSAS.CreateCloudBlobClient();
// Now set the service properties for the Blob client created with the SAS.
blobClientWithSAS.SetServiceProperties(new ServiceProperties()
{
HourMetrics = new MetricsProperties()
{
MetricsLevel = MetricsLevel.ServiceAndApi,
RetentionDays = 7,
Version = "1.0"
},
MinuteMetrics = new MetricsProperties()
{
MetricsLevel = MetricsLevel.ServiceAndApi,
RetentionDays = 7,
Version = "1.0"
},
Logging = new LoggingProperties()
{
LoggingOperations = LoggingOperations.All,
RetentionDays = 14,
Version = "1.0"
}
});
// The permissions granted by the account SAS also permit you to retrieve service properties.
ServiceProperties serviceProperties = blobClientWithSAS.GetServiceProperties();
Console.WriteLine(serviceProperties.HourMetrics.MetricsLevel);
Console.WriteLine(serviceProperties.HourMetrics.RetentionDays);
Console.WriteLine(serviceProperties.HourMetrics.Version);
}
```
## [Microsoft Teams Webhook](https://learn.microsoft.com/en-us/microsoftteams/platform/webhooks-and-connectors/how-to/connectors-using)
以下のコマンドが `Summary or Text is required.` を返す場合、URL は有効です。`Invalid webhook URL` またはその他の応答を返す場合は、URL が無効であることを意味します。```
curl -H "Content-Type:application/json" -d "{'text':''}" "YOUR_WEBHOOK_URL"
```
## [New Relic パーソナルAPIキー (NerdGraph)](https://docs.newrelic.com/docs/apis/nerdgraph/get-started/introduction-new-relic-nerdgraph#endpoint)```
curl -X POST https://api.newrelic.com/graphql \
-H 'Content-Type: application/json' \
-H 'API-Key: YOUR_API_KEY' \
-d '{ "query": "{ requestContext { userId apiKey } }" } '
```
## [New Relic REST API](https://docs.newrelic.com/docs/apis/rest-api-v2/application-examples-v2/list-your-app-id-metric-timeslice-data-v2)```
curl -X GET 'https://api.newrelic.com/v2/applications.json' \
-H "X-Api-Key:${APIKEY}" -i
```
有効な場合は、さらにテストして[管理者キー](https://docs.newrelic.com/docs/apis/get-started/intro-apis/types-new-relic-api-keys#admin)かどうかを確認してください。
## [Heroku APIキー](https://devcenter.heroku.com/articles/platform-api-quickstart)```
curl -X POST https://api.heroku.com/apps -H "Accept: application/vnd.heroku+json; version=3" -H "Authorization: Bearer API_KEY_HERE"
```
## [Mapbox APIキー](https://docs.mapbox.com/api/)
Mapboxのシークレットキーは `sk` で始まり、その他は `pk`(パブリックトークン)、`sk`(シークレットトークン)、または `tk`(一時トークン)で始まります。```
curl "https://api.mapbox.com/geocoding/v5/mapbox.places/Los%20Angeles.json?access_token=ACCESS_TOKEN"
#Check token validity
curl "https://api.mapbox.com/tokens/v2?access_token=YOUR_MAPBOX_ACCESS_TOKEN"
#Get list of all tokens associated with an account. (only works if the token is a Secret Token (sk), and has the appropiate scope)
curl "https://api.mapbox.com/tokens/v2/MAPBOX_USERNAME_HERE?access_token=YOUR_MAPBOX_ACCESS_TOKEN"
```
## [Salesforce APIキー](https://developer.salesforce.com/docs/atlas.en-us.api_rest.meta/api_rest/quickstart_oauth.htm)```
curl https://instance_name.salesforce.com/services/data/v20.0/ -H 'Authorization: Bearer access_token_here'
```
## [Algolia API key](https://www.algolia.com/doc/rest-api/search/#overview)
キーが `listIndexes` 権限を持っている場合、インデックスを一覧表示できます:```
curl --request GET \
--url https://<example-app-id>-1.algolianet.com/1/indexes/ \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-appid>'
```
そうでなければ、インデックスの名前を知る必要があります(アプリのソースコードやそれが行うリクエストを確認してください)。その後、その内容を列挙するには:```
curl --request GET \
--url https://<example-app-id>-1.algolianet.com/1/indexes/<example-index> \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-appid>'
```
このコマンドを実行する際は注意してください。編集する `highlightPreTag` のインデックスによっては、ペイロードが管理環境内で実行される可能性があります。クロスサイトスクリプティング攻撃の可能性を証明するには、より静かなペイロード(XSS Hunterなど)を使用することを推奨します。```
curl --request PUT \
--url https://<application-id>-1.algolianet.com/1/indexes/<example-index>/settings \
--header 'content-type: application/json' \
--header 'x-algolia-api-key: <example-key>' \
--header 'x-algolia-application-id: <example-application-id>' \
--data '{"highlightPreTag": "<script>alert(1);</script>"}'
```
## [Zapier Webhook トークン](https://zapier.com/help/how-get-started-webhooks-zapier/)```
curl -H "Accept: application/json" -H "Content-Type: application/json" -X POST -d '{"name":"streaak"}' "webhook_url_here"
```
## [Pagerduty API トークン](https://support.pagerduty.com/docs/using-the-api)```
curl -H "Accept: application/vnd.pagerduty+json;version=2" -H "Authorization: Token token=TOKEN_HERE" -X GET "https://api.pagerduty.com/schedules"
```
## [BrowserStack アクセスキー](https://www.browserstack.com/automate/rest-api)```
curl -u "USERNAME:ACCESS_KEY" https://api.browserstack.com/automate/plan.json
```
## [Google Maps APIキー](https://developers.google.com/maps/documentation/javascript/get-api-key)
**キーの制限はサービスごとに設定されています。キーをテストする際、あるサービスで制限/無効になっている場合は、別のサービスで試してください。**
| 名前| エンドポイント| 価格|
| ------------- |:-------------:| -----:|
| 静的マップ | https://maps.googleapis.com/maps/api/staticmap?center=45%2C10&zoom=7&size=400x400&key=KEY_HERE| $2 |
| ストリートビュー | https://maps.googleapis.com/maps/api/streetview?size=400x400&location=40.720032,-73.988354&fov=90&heading=235&pitch=10&key=KEY_HERE| $7 |
| 埋め込み | https://www.google.com/maps/embed/v1/place?q=place_id:ChIJyX7muQw8tokR2Vf5WBBk1iQ&key=KEY_HERE| 変動 |
| 道順 | https://maps.googleapis.com/maps/api/directions/json?origin=Disneyland&destination=Universal+Studios+Hollywood4&key=KEY_HERE| $5 |
| ジオコーディング | https://maps.googleapis.com/maps/api/geocode/json?latlng=40,30&key=KEY_HERE| $5 |
| 距離行列| https://maps.googleapis.com/maps/api/distancematrix/json?units=imperial&origins=40.6655101,-73.89188969999998&destinations=40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.6905615%2C-73.9976592%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626%7C40.659569%2C-73.933783%7C40.729029%2C-73.851524%7C40.6860072%2C-73.6334271%7C40.598566%2C-73.7527626&key=KEY_HERE | $5 |
|テキストから場所を検索 | https://maps.googleapis.com/maps/api/place/findplacefromtext/json?input=Museum%20of%20Contemporary%20Art%20Australia&inputtype=textquery&fields=photos,formatted_address,name,rating,opening_hours,geometry&key=KEY_HERE | 変動 |
| オートコンプリート | https://maps.googleapis.com/maps/api/place/autocomplete/json?input=Bingh&types=%28cities%29&key=KEY_HERE| 変動 |
| 標高 | https://maps.googleapis.com/maps/api/elevation/json?locations=39.7391536,-104.9847034&key=KEY_HERE | $5 |
| タイムゾーン | https://maps.googleapis.com/maps/api/timezone/json?location=39.6034810,-119.6822510×tamp=1331161200&key=KEY_HERE | $5 |
| 道路 | https://roads.googleapis.com/v1/nearestRoads?points=60.170880,24.942795\|60.170879,24.942796\|60.170877,24.942796&key=KEY_HERE | $10|
| 位置情報取得 | https://www.googleapis.com/geolocation/v1/geolocate?key=KEY_HERE| $5 |
*\*価格は1000リクエストあたりの米ドル(最初の10万リクエストまで)*
詳細情報はこちら-
https://medium.com/@ozguralp/unauthorized-google-maps-api-key-usage-cases-and-why-you-need-to-care-1ccb28bf21e
https://github.com/ozguralp/gmapsapiscanner/
https://developers.google.com/maps/api-key-best-practices
## [Google Recaptchaキー](https://developers.google.com/recaptcha/docs/verify)
以下のURLにPOSTリクエストを送信します。```
https://www.google.com/recaptcha/api/siteverify
```
`secret` と `response` は必須のPOSTパラメータです。`secret` はキー、`response` はテストする応答です。
正規表現: `^6[0-9a-zA-Z_-]{39}$`。APIキーは常に6で始まり、40文字の長さです。詳細はこちら: https://developers.google.com/recaptcha/docs/verify。
## [Google Cloud サービスアカウント認証情報](https://cloud.google.com/docs/authentication/production)
サービスアカウント認証情報は、以下のようなJSONファイルに含まれています:```
$ cat service_account.json
{
"type": "service_account",
"project_id": "...",
"private_key_id": "...",
"private_key": "-----BEGIN PRIVATE KEY-----...-----END PRIVATE KEY-----\n",
"client_email": "...",
"client_id": "...",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_x509_cert_url": "https://www.googleapis.com/robot/v1/metadata/x509/..."
}
```
もしこれがあなたのケースであれば、`gcloud` ツールを使用してこれらの認証情報を確認できます([`gcloud` のインストール方法](https://cloud.google.com/sdk/docs/quickstart-debian-ubuntu)):```
$ gcloud auth activate-service-account --key-file=service_account.json
Activated service account credentials for: [...]
$ gcloud auth print-access-token
ya29.c...
```
成功した場合、アクセストークンがターミナルに表示されます。認証情報が実際に有効であることを確認した後、これらの認証情報の権限を列挙したい場合があるかもしれませんが、それは別の話です。
## [Branch.IO キーとシークレット](https://docs.branch.io/pages/apps/deep-linking-api/#app-read)
有効性を確認するには、次の URL にアクセスしてください:```
https://api2.branch.io/v1/app/KEY_HERE?branch_secret=SECRET_HERE
```
## [Bing Maps API キー](https://docs.microsoft.com/en-us/bingmaps/rest-services/locations/find-a-location-by-address)
このリンクにアクセスしてキーの有効性を確認してください。有効なキーのレスポンスは `authenticationResultCode: "ValidCredentials"` で始まる必要があります。```
https://dev.virtualearth.net/REST/v1/Locations?CountryRegion=US&adminDistrict=WA&locality=Somewhere&postalCode=98001&addressLine=100%20Main%20St.&key=API_KEY
```
## [Bit.ly アクセストークン](https://dev.bitly.com/authentication.html)
以下のURLにアクセスして有効性を確認してください:```
https://api-ssl.bitly.com/v3/shorten?access_token=ACCESS_TOKEN&longUrl=https://www.google.com
```
## [Buildkite アクセストークン](https://buildkite.com/docs/apis/rest-api)```
curl -H "Authorization: Bearer ACCESS_TOKEN" \
https://api.buildkite.com/v2/access-token
```
## [ButterCMS-API-Key](https://buttercms.com/docs/api/#authentication)```
curl -X GET 'https://api.buttercms.com/v2/posts/?auth_token=your_api_token'
```
## [Asana アクセストークン](https://asana.com/developers/documentation/getting-started/auth#personal-access-token)```
curl -H "Authorization: Bearer ACCESS_TOKEN" https://app.asana.com/api/1.0/users/me
```
## [Zendesk アクセストークン](https://support.zendesk.com/hc/en-us/articles/203663836-Using-OAuth-authentication-with-your-application)```
curl https://{subdomain}.zendesk.com/api/v2/tickets.json \
-H "Authorization: Bearer ACCESS_TOKEN"
```
## [Zendesk Api Key](https://developer.zendesk.com/api-reference/ticketing/introduction/)
APIトークンはOAuthトークンとは異なります、APIトークンはSupport管理インターフェースで自動生成されるパスワードです。```
curl https://{target}.zendesk.com/api/v2/users.json \ -u support@{target}.com/token:{here your token}
```
## [MailChimp APIキー](https://developer.mailchimp.com/documentation/mailchimp/reference/overview/)```
curl --request GET --url 'https://<dc>.api.mailchimp.com/3.0/' --user 'anystring:<API_KEY>' --include
```
## [WPEngine APIキー](https://wpengineapi.com/)
この問題は、[@hateshape](https://github.com/hateshape/) のgist https://gist.github.com/hateshape/2e671ea71d7c243fac7ebf51fb738f0a を参照することでさらに悪用可能です。```
curl "https://api.wpengine.com/1.2/?method=site&account_name=ACCOUNT_NAME&wpe_apikey=WPENGINE_APIKEY"
```
## [DataDog API key](https://docs.datadoghq.com/api/)```
curl "https://api.datadoghq.com/api/v1/dashboard?api_key=<api_key>&application_key=<application_key>"
```
## [Delighted APIキー](https://app.delighted.com/docs/api)
末尾の `:` を削除しないでください。```
curl https://api.delighted.com/v1/metrics.json \
-H "Content-Type: application/json" \
-u YOUR_DELIGHTED_API_KEY:
```
## [Travis CI API トークン](https://developer.travis-ci.com/gettingstarted)```
curl -H "Travis-API-Version: 3" -H "Authorization: token <TOKEN>" https://api.travis-ci.org/repos
```
## [Telegram Bot API トークン](https://core.telegram.org/bots/api#making-requests)```
curl https://api.telegram.org/bot<TOKEN>/getMe
```
## [WakaTime APIキー](https://wakatime.com/developers)```
curl "https://wakatime.com/api/v1/users/current?api_key=KEY_HERE"
```
## [Sonarcloud トークン](https://sonarcloud.io/web_api)```
curl -u <token>: "https://sonarcloud.io/api/authentication/validate"
```
## [Spotify アクセストークン](https://developer.spotify.com/documentation/general/guides/authorization-guide/)```
curl -H "Authorization: Bearer <ACCESS_TOKEN>" https://api.spotify.com/v1/me
```
## [Instagram Basic Display API アクセストークン](https://developers.facebook.com/docs/instagram-basic-display-api/getting-started)
例:IGQVJ...```
curl -X GET 'https://graph.instagram.com/{user-id}?fields=id,username&access_token={access-token}'
```
## [Instagram Graph API アクセストークン](https://developers.facebook.com/docs/instagram-api/getting-started)
例: EAAJjmJ...```
curl -i -X GET 'https://graph.facebook.com/v8.0/me/accounts?access_token={access-token}'
```
## [GitLab 個人アクセストークン](https://docs.gitlab.com/ee/api/README.html#personal-access-tokens)```
curl "https://gitlab.example.com/api/v4/projects?private_token=<your_access_token>"
```
## [GitLabランナー登録トークン](https://docs.gitlab.com/runner/register/)```
docker run --rm gitlab/gitlab-runner register \
--non-interactive \
--executor "docker" \
--docker-image alpine:latest \
--url "https://gitlab.com/" \
--registration-token "PROJECT_REGISTRATION_TOKEN" \
--description "keyhacks-test" \
--maintenance-note "Testing token with keyhacks" \
--tag-list "docker,aws" \
--run-untagged="true" \
--locked="false" \
--access-level="not_protected"
```
## [Paypal クライアントIDとシークレットキー](https://developer.paypal.com/docs/api/get-an-access-token-curl/)```
curl -v https://api.sandbox.paypal.com/v1/oauth2/token \
-H "Accept: application/json" \
-H "Accept-Language: en_US" \
-u "client_id:secret" \
-d "grant_type=client_credentials"
```
アクセストークンは、PayPal APIからデータを抽出するためにさらに使用できます。詳細情報:https://developer.paypal.com/docs/api/overview/#make-rest-api-calls.
これは以下を使用して確認できます:```
curl -v -X GET "https://api.sandbox.paypal.com/v1/identity/oauth2/userinfo?schema=paypalv1.1" -H "Content-Type: application/json" -H "Authorization: Bearer [ACCESS_TOKEN]"
```
## [Stripe Live Token](https://stripe.com/docs/api/authentication)```
curl https://api.stripe.com/v1/charges -u token_here:
```
トークンの末尾にコロンを残すことで、`cURL`がパスワードを要求するのを防ぎます。
トークンは常に `sk_live_24charshere` の形式で、`24charshere` の部分は `a-z A-Z 0-9` の24文字で構成されます。また、`sk_test` で始まるテストキーも存在しますが、これはテスト目的のみで使用され、機密情報を含まないため価値がありません。一方、ライブキーは、料金から完全な商品リストに至るまで、多くの情報を抽出/取得するために使用できます。
Stripeはクレジットカードの完全な情報を提供せず、最後の4桁のみを返すことに注意してください。
詳細情報/完全なドキュメント: https://stripe.com/docs/api/authentication
## [Razorpay APIキーとシークレットキー](https://razorpay.com/docs/api/)
これは以下を使用して確認できます:```
curl -u <YOUR_KEY_ID>:<YOUR_KEY_SECRET> \
https://api.razorpay.com/v1/payments
```
## [CircleCI Access Token](https://circleci.com/docs/api/#api-overview)```
curl https://circleci.com/api/v1.1/me?circle-token=<TOKEN>
```
## [Cloudflare APIキー](https://api.cloudflare.com/#user-api-tokens-verify-token)```
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
-H "Authorization: Bearer <YOUR_API_TOKEN>"
```
## [Loqate APIキー](https://www.loqate.com/resources/support/apis)```
curl 'http://api.addressy.com/Capture/Interactive/Find/v1.00/json3.ws?Key=<KEY_HERE>&Countries=US,CA&Language=en&Limit=5&Text=BHAR'
```
## [Ipstack API Key](https://ipstack.com/documentation)```
curl 'https://api.ipstack.com/{ip_address}?access_key={keyhere}'
```
## [NPMトークン](https://docs.npmjs.com/about-authentication-tokens)
NPMトークンは、[`npm` を使用して](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3) (`00000000-0000-0000-0000-000000000000` をNPMトークンに置き換えて) 確認できます:```
export NPM_TOKEN="00000000-0000-0000-0000-000000000000"
echo "//registry.npmjs.org/:_authToken=${NPM_TOKEN}" > .npmrc
npm whoami
```
トークンを検証する別の方法は、API を直接クエリすることです。```
curl -H 'authorization: Bearer 00000000-0000-0000-0000-000000000000' 'https://registry.npmjs.org/-/whoami'
```
成功した場合、レスポンスでユーザー名が返されます。トークンが存在しない場合は `401 Unauthorized`、IPアドレスがホワイトリストに登録されていない場合は `403 Forbidden` が返されます。
NPMトークンは[CIDRホワイトリスト化](https://docs.npmjs.com/creating-and-viewing-authentication-tokens#creating-tokens-with-the-cli)できます。したがって、ホワイトリストに登録されていないCIDRからのトークンを使用すると、レスポンスで `403 Forbidden` が返されます。異なるIP範囲からNPMトークンを検証してみてください!
P.S. 一部の企業は[`registry.npmjs.org` 以外のレジストリを使用しています](https://medium.com/bugbountywriteup/one-token-to-leak-them-all-the-story-of-a-8000-npm-token-79b13af182a3)。その場合は、すべての `registry.npmjs.org` を会社のNPMレジストリのドメイン名に置き換えてください。
## [OpsGenie APIキー](https://docs.opsgenie.com/docs/api-overview)```
curl https://api.opsgenie.com/v2/alerts -H 'Authorization: GenieKey API_KEY'
```
## [Keen.io APIキー](https://keen.io/docs/api/)
特定のプロジェクトのすべてのコレクションを取得する:```
curl "https://api.keen.io/3.0/projects/PROJECT_ID/events?api_key=READ_KEY"
```
> 注:cURLがパスワードを要求しないように、トークンの末尾にコロンを付けてください。
情報: トークンは常に次の形式です: sk_live_34charshere、ここで34charshere部分はa-z A-Z 0-9の34文字で構成されています。
また、sk_testで始まるテストキーもありますが、このキーはテスト目的でのみ使用され、機密情報を含まない可能性が高いため無価値です。
一方、ライブキーは多くの情報を抽出/取得するために使用できます。チャージから完全な製品リストまで。
Stripeはクレジットカード情報の下4桁程度しか提供しないため、完全なクレジットカード情報を取得することはできないことに注意してください。
詳細情報/完全なドキュメント: https://stripe.com/docs/api/authentication
=======
## [Calendly API Key](https://developer.calendly.com/docs/)
ユーザー情報を取得:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/users/me
````
ウェブフック購読一覧:````
curl --header "X-TOKEN: <your_token>" https://calendly.com/api/v1/hooks
````
## [Azure Application Insights APP ID and API Key](https://dev.applicationinsights.io/reference)
過去24時間に行われたリクエストの総数を取得します:```
curl -H "x-api-key: {API_Key}" "https://api.applicationinsights.io/v1/apps/{APP_ID}/metrics/requests/count"
```
## [Cypress record key](https://docs.cypress.io/guides/dashboard/projects.html#Record-key)
`recordKey`の有効性を確認するには、通常`cypress.json`ファイルに含まれている公開値である`projectId`が必要です。JSON本文内の`{recordKey}`と`{projectId}`をそれぞれの値に置き換えてください。```
curl -i -s -k -X $'POST' \
-H $'x-route-version: 4' -H $'x-os-name: darwin' -H $'x-cypress-version: 5.5.0' -H $'host: api.cypress.io' -H $'accept: application/json' -H $'content-type: application/json' -H $'Content-Length: 1433' -H $'Connection: close' \
--data-binary $'{\"ci\":{\"params\":null,\"provider\":null},\"specs\":[\"cypress/integration/examples/actions.spec.js\",\"cypress/integration/examples/aliasing.spec.js\",\"cypress/integration/examples/assertions.spec.js\",\"cypress/integration/examples/connectors.spec.js\",\"cypress/integration/examples/cookies.spec.js\",\"cypress/integration/examples/cypress_api.spec.js\",\"cypress/integration/examples/files.spec.js\",\"cypress/integration/examples/local_storage.spec.js\",\"cypress/integration/examples/location.spec.js\",\"cypress/integration/examples/misc.spec.js\",\"cypress/integration/examples/navigation.spec.js\",\"cypress/integration/examples/network_requests.spec.js\",\"cypress/integration/examples/querying.spec.js\",\"cypress/integration/examples/spies_stubs_clocks.spec.js\",\"cypress/integration/examples/traversal.spec.js\",\"cypress/integration/examples/utilities.spec.js\",\"cypress/integration/examples/viewport.spec.js\",\"cypress/integration/examples/waiting.spec.js\",\"cypress/integration/examples/window.spec.js\"],\"commit\":{\"sha\":null,\"branch\":null,\"authorName\":null,\"authorEmail\":null,\"message\":null,\"remoteOrigin\":null,\"defaultBranch\":null},\"group\":null,\"platform\":{\"osCpus\":[],\"osName\":\"darwin\",\"osMemory\":{\"free\":1153744896,\"total\":17179869184},\"osVersion\":\"19.6.0\",\"browserName\":\"Electron\",\"browserVersion\":\"85.0.4183.121\"},\"parallel\":null,\"ciBuildId\":null,\"projectId\":\"{projectId}\",\"recordKey\":\"{recordKey}\",\"specPattern\":null,\"tags\":[\"\"]}' \
$'https://api.cypress.io/runs'
```
はい、このリクエストはそのくらい大きい必要があります。`projectId`と`recordKey`の両方が有効な場合は、実行に関する情報を含む`200 OK`を返します。`projectId`が無効な場合は`404 Not Found`と`{"message":"Project not found. Invalid projectId."}`を、`recordKey`が無効な場合は`401 Unauthorized`と`{"message":"Invalid Record Key."}`を返します。
`projectId`の例は`1yxykz`、`recordKey`の例は`a216e7b4-4819-4713-b9c2-c5da60a1c48c`です。
## [YouTube API キー](https://developers.google.com/youtube/v3/docs/)
YouTubeチャンネルのコンテンツ詳細を取得します(この場合、channelIdはPewDiePieのチャンネルを指します)。```
curl -iLk 'https://www.googleapis.com/youtube/v3/activities?part=contentDetails&maxResults=25&channelId=UC-lHJZR3Gqxm24_Vd_AJ5Yw&key={KEY_HERE}'
```
## [ABTasty API キー](https://developers.abtasty.com/server-side.html#authentication)```
curl "api_endpoint_here" -H "x-api-key: your_api_key"
```
## [Iterable API Key](https://api.iterable.com/api/docs)
キャンペーン分析データをJSON形式で、1行に1エントリずつエクスポートします。'range'または'startDateTime'と'endDateTime'のいずれかを使用する必要があります。```
curl -H "Api_Key: {API_KEY}" https://api.iterable.com/api/export/data.json?dataTypeName=emailSend&range=Today&onlyFields=List.empty
```
## [Amplitude API キー](https://help.amplitude.com/hc/en-us/articles/205406637-Export-API-Export-Your-Project-s-Event-Data)
このレスポンスは、JSONファイルが圧縮されたアーカイブであり、1時間あたり複数のファイルが含まれる可能性があります。なお、2014-11-12より前のイベントは、時間単位ではなく日単位でグループ化されます。プロジェクトに対してデータが収集されていない時間範囲のデータをリクエストした場合、サーバーから404レスポンスが返されます。```
curl -u API_Key:Secret_Key 'https://amplitude.com/api/2/export?start=20200201T5&end=20210203T20' >> yourfilename.zip
```
## [Visual Studio App Center API トークン](https://docs.microsoft.com/en-us/appcenter/api-docs/)
1. API トークンのすべてのアプリプロジェクトを一覧表示する: ```
curl -sX GET "https://api.appcenter.ms/v0.1/apps" \
-H "Content-Type: application/json" \
-H "X-Api-Token: {your_api_token}"
```
2. 特定のプロジェクトの最新のアプリビルド情報を取得する:
> Step [1](#438)のレスポンスで取得した `name` と `owner.name` を使用してください。 ```
curl -sX GET "https://api.appcenter.ms/v0.1/apps/{owner.name}/{name}/releases/latest" \
-H "Content-Type: application/json" \
-H "X-Api-Token: {your_api_token}"
```
## [WeGlot API キー](https://weglot.com/)```
curl -X POST \
'https://api.weglot.com/translate?api_key=my_api_key' \
-H 'Content-Type: application/json' \
-d '{
"l_from":"en",
"l_to":"fr",
"request_url":"https://www.website.com/",
"words":[
{"w":"This is a blue car", "t": 1},
{"w":"This is a black car", "t": 1}
]
}'
```
## [PivotalTracker API トークン](https://www.pivotaltracker.com/help/api/#top)
1. API トークンを使用してユーザー情報を一覧表示する: ```
curl -X GET -H "X-TrackerToken: $TOKEN" "https://www.pivotaltracker.com/services/v5/me?fields=%3Adefault"
```
1. 有効なユーザー認証情報でAPIトークンを取得する: ```
curl -s -X GET --user 'USER:PASSWORD' "https://www.pivotaltracker.com/services/v5/me -o pivotaltracker.json"
jq --raw-output .api_token pivotaltracker.json
```
## [LinkedIn OAuth](https://docs.microsoft.com/en-us/linkedin/shared/authentication/client-credentials-flow?context=linkedin/context)
アクセストークンリクエストが成功すると、access_token と expires_in を含む JSON オブジェクトが返されます。```
curl -XPOST -H "Content-type: application/x-www-form-urlencoded" -d 'grant_type=client_credentials&client_id=<client-ID>&client_secret=<client-secret>' 'https://www.linkedin.com/oauth/v2/accessToken'
```
## [Help Scout OAUTH](https://developer.helpscout.com/mailbox-api/overview/authentication/)
アクセストークン要求が成功すると、token_type、access_token、expires_in を含む JSON オブジェクトが返されます。```
curl -X POST https://api.helpscout.net/v2/oauth2/token \
--data "grant_type=client_credentials" \
--data "client_id={application_id}" \
--data "client_secret={application_secret}"
```
## [Shodan APIキー](https://developer.shodan.io/api/requirements)```
curl "https://api.shodan.io/shodan/host/8.8.8.8?key=TOKEN_HERE"
```
## [Bazaarvoice Passkey](https://developer.bazaarvoice.com/conversations-api/home)
成功したPasskeyリクエストは、会社名を含むJSONオブジェクトを返します。```
curl 'https://which-cpv-api.bazaarvoice.com/clientInfo?conversationspasskey=<Passkey>' --insecure
```
## [Grafana アクセストークン](https://grafana.com/docs/grafana/latest/developers/http_api/user/)
Grafana APIはBearer認証方式とBasic認証方式をサポートしています。Bearer:```
curl -s -H "Authorization: Bearer your-api-key" http://your-grafana-server-url.com/api/user
```
基本:```
curl -u username:password http://your-grafana-server-url.com/api/user
```
# Contributing
皆様からのコントリビューションを歓迎します。
### 課題トラッカーの使用方法 💡
課題トラッカーは、バグ報告や機能リクエストのための推奨チャネルです。
### 課題とラベル 🏷
バグトラッカーでは、課題の整理と識別のためにいくつかのラベルを使用しています。
### バグ報告のガイドライン 🐛
GitHubの課題検索を使用してください — 既に報告されているかどうかを確認してください。
# ⚠ 法的免責事項
このプロジェクトは、教育および倫理的なテスト目的のみで作成されています。事前の相互同意なしにターゲットを攻撃するためにこのツールを使用することは違法です。開発者は一切の責任を負わず、このツールの誤用や損害について責任を負いません。