Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
keyhacks — 精心整理的命令集合,用于验证来自漏洞赏金计划和渗透测试的泄露 API 密钥,涵盖 80+ 种服务,包括 AWS、GitHub、Slack 和 Twilio。 | Kitploit
工具/GitHubGitHub/streaak/keyhacks
漏洞分析渗透测试秘密检测API 安全
GitHubstreaak/keyhacks

keyhacks

精心整理的命令集合,用于验证来自漏洞赏金计划和渗透测试的泄露 API 密钥,涵盖 80+ 种服务,包括 AWS、GitHub、Slack 和 Twilio。

查看仓库
6.3k1.2k411个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享


KeyHacks 展示了在漏洞赏金计划或渗透测试中发现的不同 API 密钥的验证方法。

@Gwen001 已将整个过程编写成脚本,可在此处获取:here

目录

  • ABTasty API 密钥
  • Algolia API 密钥
  • Amplitude API 密钥
  • Asana 访问令牌
  • AWS 访问密钥 ID 和密钥
  • Azure Application Insights APP ID 和 API 密钥
  • Bazaarvoice 通行密钥
  • Bing Maps API 密钥
  • Bit.ly 访问令牌
  • Branch.io 密钥和密钥
  • BrowserStack 访问密钥
  • Buildkite 访问令牌
  • ButterCMS API 密钥
  • Calendly API 密钥
  • Contentful 访问令牌
  • CircleCI 访问令牌
  • Cloudflare API 密钥
  • Cypress 记录密钥
  • DataDog API 密钥
  • Delighted API 密钥
  • Deviant Art 访问令牌
  • Deviant Art 密钥
  • Dropbox API
  • Facebook 访问令牌
  • Facebook AppSecret
  • Firebase
  • Firebase Cloud Messaging (FCM)
  • FreshDesk API 密钥
  • Github 客户端 ID 和客户端密钥
  • GitHub 私有 SSH 密钥
  • Github 令牌
  • Gitlab 个人访问令牌
  • GitLab Runner 注册令牌
  • Google Cloud 服务账号凭据
  • Google Maps API 密钥
  • Google Recaptcha 密钥
  • Grafana 访问令牌
  • Help Scout OAUTH
  • Heroku API 密钥
  • HubSpot API 密钥
  • Infura API 密钥
  • Instagram 访问令牌
  • Instagram Basic Display API 访问令牌
  • Instagram Graph API 访问令牌
  • Ipstack API 密钥
  • Iterable API 密钥
  • JumpCloud API 密钥
  • Keen.io API 密钥
  • LinkedIn OAUTH
  • Lokalise API 密钥
  • Loqate API 密钥
  • MailChimp API 密钥
  • MailGun 私钥
  • Mapbox API 密钥
  • Microsoft Azure 租户
  • Microsoft 共享访问签名 (SAS)
  • Microsoft Teams Webhook
  • New Relic 个人 API 密钥 (NerdGraph)
  • New Relic REST API
  • NPM 令牌
  • OpsGenie API 密钥
  • PagerDuty API 令牌
  • Paypal 客户端 ID 和密钥
  • Pendo 集成密钥
  • PivotalTracker API 令牌
  • Razorpay API 密钥和密钥
  • Salesforce API 密钥
  • SauceLabs 用户名和访问密钥
  • SendGrid API 令牌
  • Shodan.io API 密钥
  • Slack API 令牌
  • Slack Webhook
  • SonarCloud 令牌
  • Spotify 访问令牌
  • Square
  • Stripe 实时令牌
  • Telegram Bot API 令牌
  • Travis CI API 令牌
  • Twilio Account SID 和 Auth 令牌
  • Twitter API 密钥
  • Twitter Bearer 令牌
  • Visual Studio App Center API 令牌
  • WakaTime API 密钥
  • WeGlot API 密钥
  • WPEngine API 密钥
  • YouTube API 密钥
  • Zapier Webhook 令牌
  • Zendesk 访问令牌
  • Zendesk API 密钥

详细信息

Slack Webhook

如果以下命令返回 missing_text_or_fallback_or_attachments,则表示该 URL 有效,任何其他响应则表示该 URL 无效。``` curl -s -X POST -H "Content-type: application/json" -d '{"text":""}' "https://hooks.slack.com/services/T00000000/B00000000/XXXXXXXXXXXXXXXXXXXXXXXX"

## [Slack API 令牌](https://api.slack.com/web)```
curl -sX POST "https://slack.com/api/auth.test?token=xoxp-TOKEN_HERE&pretty=1"

或者``` curl -sX POST "https://slack.com/api/auth.test" -H "Accept: application/json; charset=utf-8" -H "Authorization: Bearer xoxb-TOKEN_HERE"

## [SauceLabs 用户名和访问密钥](https://wiki.saucelabs.com/display/DOCS/Account+Methods)```
curl -u USERNAME:ACCESS_KEY https://saucelabs.com/rest/v1/users/USERNAME

Facebook AppSecret

您可以通过访问以下URL来生成访问令牌。``` https://graph.facebook.com/oauth/access_token?client_id=ID_HERE&client_secret=SECRET_HERE&redirect_uri=&grant_type=client_credentials

## Facebook 访问令牌```
https://developers.facebook.com/tools/debug/accesstoken/?access_token=ACCESS_TOKEN_HERE&version=v3.2

Firebase

需要自定义令牌和API密钥。

  1. 通过自定义令牌和API密钥获取ID令牌和刷新令牌:curl -s -XPOST -H 'content-type: application/json' -d '{"token":":custom_token","returnSecureToken":True}' 'https://identitytoolkit.googleapis.com/v1/accounts:signInWithCustomToken?key=:api_key'
  2. 将ID令牌交换为身份验证令牌:curl -s -XPOST -H 'content-type: application/json' -d '{"idToken":":id_token"}' https://www.googleapis.com/identitytoolkit/v3/relyingparty/verifyCustomToken?key=:api_key'

Github Token```

curl -s -u "user:apikey" https://api.github.com/user curl -s -H "Authorization: token TOKEN_HERE" "https://api.github.com/users/USERNAME_HERE/orgs"

Check scope of your api token

curl "https://api.github.com/rate_limit" -i -u "user:apikey" | grep "X-OAuth-Scopes:"

## [Github客户端ID和客户端密钥](https://developer.github.com/v3/#oauth2-keysecret)```
curl 'https://api.github.com/users/whatever?client_id=xxxx&client_secret=yyyy'

Firebase Cloud Messaging

参考:https://abss.me/posts/fcm-takeover``` curl -s -X POST --header "Authorization: key=AI..." --header "Content-Type:application/json" 'https://fcm.googleapis.com/fcm/send' -d '{"registration_ids":["1"]}'

## GitHub 私有 SSH 密钥

SSH 私钥可以针对 github.com 进行测试,以查看它们是否已注册到现有用户账户。如果密钥存在,将提供与该密钥对应的用户名。([source](https://github.com/streaak/keyhacks/issues/2))```
$ ssh -i <path to SSH private key> -T [email protected]
Hi <username>! You've successfully authenticated, but GitHub does not provide shell access.

Twilio Account_sid and Auth token```

curl -X GET 'https://api.twilio.com/2010-04-01/Accounts.json' -u ACCOUNT_SID:AUTH_TOKEN

## [Twitter API 密钥](https://developer.twitter.com/en/docs/basics/authentication/guides/bearer-tokens.html)```
curl -u 'API key:API secret key' --data 'grant_type=client_credentials' 'https://api.twitter.com/oauth2/token'

Twitter 持有者令牌```

curl --request GET --url https://api.twitter.com/1.1/account_activity/all/subscriptions/count.json --header 'authorization: Bearer TOKEN'

## [HubSpot API 密钥](https://developers.hubspot.com/docs/methods/owners/get_owners)

获取所有所有者:```
https://api.hubapi.com/owners/v2/owners?hapikey={keyhere}

获取所有联系方式:``` https://api.hubapi.com/contacts/v1/lists/all/contacts/all?hapikey={keyhere}

下载工具