Secret and/ credential patterns used for gf
.
- Have
gf
in your machine. Install now if not ready!
Clone this repository.
▶ git clone https://github.com/dwisiswant0/gf-secrets
Then copy all JSON pattern files into ~/.gf
directory.
▶ cd gf-secrets/
▶ cp -a .gf/ $HOME
Finding for testing point with gau and fff.
▶ gau [host] -subs | cut -d"?" -f1 | grep -E "\.js(?:onp?)?$" | tee urls.txt
▶ sort -u urls.txt | fff -s 200 -o out/
After we save response from known URLs, it's time to digging for secrets.
▶ for i in `gf -list`; do [[ ${i} =~ "_secrets"* ]] && gf ${i}; done
You will see stdout results in your terminal if grep recursively turns match.
If you find a general pattern for secrets and/ credentials, feel free to open pull request. 💚
The JSON files and documentation in this project are released under the MIT License.
Tools used with this project include third party materials.