Secret and/or credential patterns used for gf
.
- Have
gf
in your machine. Install now if not ready!
Clone this repository.
▶ git clone https://github.com/dwisiswant0/gf-secrets
Then copy all JSON pattern files into ~/.gf
directory.
▶ cd gf-secrets/
▶ cp -a .gf/ $HOME
See also:
- secpat2gf: convert secret patterns to gf compatible.
Finding for testing point with gau and fff.
▶ gau -subs [host] | cut -d"?" -f1 | grep -E "\.js(onp?)?$" | tee urls.txt
▶ sort -u urls.txt | fff -s 200 -o out/
After we save response from known URLs, it's time to digging for secrets.
▶ ./gf-secrets.sh
You will see stdout results in your terminal if grep recursively turns match.
If you find a general pattern for secrets and/or credentials, feel free to open pull request. 💚
The JSON files and documentation in this project are released under the MIT License.
Tools used with this project include third party materials.