KeyHacks 展示了在漏洞赏金计划或渗透测试中发现的不同 API 密钥的验证方法。
@Gwen001 已将整个过程编写成脚本,可在此处获取:here
如果以下命令返回 missing_text_or_fallback_or_attachments,则表示该 URL 有效,任何其他响应则表示该 URL 无效。```
curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"
## [Slack API 令牌](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"
或者``` curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"
## [SauceLabs 用户名和访问密钥](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME
您可以通过访问以下URL来生成访问令牌。``` https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials
## Facebook 访问令牌```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2
需要自定义令牌和API密钥。
curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'curl -s -u "user:apikey" https://api.github.com/user curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"
curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"
## [Github客户端ID和客户端密钥](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'
参考:https://abss.me/posts/fcm-takeover``` curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'
## GitHub 私有 SSH 密钥
SSH 私钥可以针对 github.com 进行测试,以查看它们是否已注册到现有用户账户。如果密钥存在,将提供与该密钥对应的用户名。([source](https://github.com/streaak/keyhacks/issues/2))```
$ ssh -i <path to SSH private key> -T [email protected]
Hi <username>! You've successfully authenticated, but GitHub does not provide shell access.
curl -X GET 'https://api.twilio.com/2010-04-01/Accounts.json' -u ACCOUNT_SID:AUTH_TOKEN
## [Twitter API 密钥](https://developer.twitter.com/en/docs/basics/authentication/guides/bearer-tokens.html)```
curl -u 'API key:API secret key' --data 'grant_type=client_credentials' 'https://api.twitter.com/oauth2/token'
curl --request GET --url https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json --header 'authorization: Bearer TOKEN'
## [HubSpot API 密钥](https://developers.hubspot.com/docs/methods/owners/get_owners)
获取所有所有者:```
https://api.hubapi.com/owners/v2/owners?hapikey={keyhere}
获取所有联系方式:``` https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={keyhere}