[Update] Added Missing Indeterminate Verification Errors In Detectors Starting With Letter "A" (#4256)
* added missing indeterminate verification errors in detectors starting from letter a * fixed atera, assemlyai detector indeterminate verification errors * added response body discard in asana detectors
This commit is contained in:
@@ -3,6 +3,7 @@ package appcues
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -13,7 +14,7 @@ import (
|
|||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
)
|
)
|
||||||
|
|
||||||
type Scanner struct{
|
type Scanner struct {
|
||||||
detectors.DefaultMultiPartCredentialProvider
|
detectors.DefaultMultiPartCredentialProvider
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -60,18 +61,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
RawV2: []byte(resMatch + resUserMatch),
|
RawV2: []byte(resMatch + resUserMatch),
|
||||||
}
|
}
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", fmt.Sprintf("https://api.appcues.com/v2/accounts/%s/flows", resIdMatch), nil)
|
isVerified, err := verifyMatch(ctx, client, resUserMatch, resMatch, resIdMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resUserMatch, resMatch, resIdMatch)
|
||||||
}
|
|
||||||
req.SetBasicAuth(resUserMatch, resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -82,6 +74,31 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, resUserMatch, resMatch, resIdMatch string) (bool, error) {
|
||||||
|
// Reference: https://api.appcues.com/v2/docs?_gl=1#responses
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, fmt.Sprintf("https://api.appcues.com/v2/accounts/%s/flows", resIdMatch), http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.SetBasicAuth(resUserMatch, resMatch)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized, http.StatusForbidden, http.StatusBadRequest:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Appcues
|
return detectorspb.DetectorType_Appcues
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ package appfollow
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -45,18 +47,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://api.appfollow.io/api/v2/account/users", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("X-AppFollow-API-Token", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -65,6 +58,31 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
// Reference: https://docs.api.appfollow.io/reference/users_list_api_v2_account_users_get-1
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://api.appfollow.io/api/v2/account/users", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("X-AppFollow-API-Token", token)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK, http.StatusPaymentRequired, http.StatusUnprocessableEntity:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Appfollow
|
return detectorspb.DetectorType_Appfollow
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,11 +2,13 @@ package appointedd
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"fmt"
|
||||||
"io"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -44,24 +46,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
Raw: []byte(resMatch),
|
Raw: []byte(resMatch),
|
||||||
}
|
}
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://api.appointedd.com/v1/availability/slots", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("X-API-KEY", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
bodyBytes, err := io.ReadAll(res.Body)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
body := string(bodyBytes)
|
|
||||||
|
|
||||||
if strings.Contains(body, "total") {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -70,6 +57,35 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, secret string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://api.appointedd.com/v1/availability/slots", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("X-API-KEY", secret)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
return strings.Contains(string(bodyBytes), "total"), nil
|
||||||
|
case http.StatusUnauthorized, http.StatusForbidden:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Appointedd
|
return detectorspb.DetectorType_Appointedd
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,10 +3,12 @@ package appsynergy
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -45,18 +47,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
payload := strings.NewReader(`{"html":"<html><body><h1>Hello World</h1></body></html>","filename":"HelloWorld.pdf"}`)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
req, err := http.NewRequestWithContext(ctx, "POST", fmt.Sprintf("https://www.appsynergy.com/api?action=HTML2PDF&apiKey=%s", resMatch), payload)
|
s1.Verified = isVerified
|
||||||
if err != nil {
|
s1.SetVerificationError(err, resMatch)
|
||||||
continue
|
|
||||||
}
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -65,6 +58,41 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, secret string) (bool, error) {
|
||||||
|
payload := strings.NewReader(`{"html":"<html><body><h1>Hello World</h1></body></html>","filename":"HelloWorld.pdf"}`)
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodPost, "https://www.appsynergy.com/api?action=HTML2PDF&apiKey="+secret, payload)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
case http.StatusBadRequest:
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
body := string(bodyBytes)
|
||||||
|
if strings.Contains(body, "Invalid API Key") {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
return false, fmt.Errorf("status bad request invalid api key message not found: %d", res.StatusCode)
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AppSynergy
|
return detectorspb.DetectorType_AppSynergy
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ import (
|
|||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
)
|
)
|
||||||
|
|
||||||
type Scanner struct{
|
type Scanner struct {
|
||||||
detectors.DefaultMultiPartCredentialProvider
|
detectors.DefaultMultiPartCredentialProvider
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -54,27 +54,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", fmt.Sprintf("https://api.apptivo.com/app/dao/v6/leads?a=getConfigData&apiKey=%s&accessKey=%s", resMatch, resIdMatch), nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch, resIdMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch, resIdMatch)
|
||||||
}
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
bodyBytes, err := io.ReadAll(res.Body)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
bodyString := string(bodyBytes)
|
|
||||||
validResponse := strings.Contains(bodyString, `displayName`)
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
if validResponse {
|
|
||||||
s1.Verified = true
|
|
||||||
} else {
|
|
||||||
s1.Verified = false
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -84,6 +66,32 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, apiKey, accessKey string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, fmt.Sprintf("https://api.apptivo.com/app/dao/v6/leads?a=getConfigData&apiKey=%s&accessKey=%s", apiKey, accessKey), http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
return strings.Contains(string(bodyBytes), `displayName`), nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Apptivo
|
return detectorspb.DetectorType_Apptivo
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ package artsy
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -54,17 +56,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "POST", "https://api.artsy.net/api/tokens/xapp_token?client_id="+resIdMatch+"&client_secret="+resMatch, nil)
|
isVerified, err := verifyMatch(ctx, client, resIdMatch, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -75,6 +69,30 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, id, secret string) (bool, error) {
|
||||||
|
// Reference: https://developers.artsy.net/v2/docs/authentication
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodPost, "https://api.artsy.net/api/tokens/xapp_token?client_id="+id+"&client_secret="+secret, http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusCreated:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Artsy
|
return detectorspb.DetectorType_Artsy
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package asanaoauth
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -46,20 +47,11 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://app.asana.com/api/1.0/users/me", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", resMatch))
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
s1.AnalysisInfo = map[string]string{"key": resMatch}
|
s1.AnalysisInfo = map[string]string{"key": resMatch}
|
||||||
}
|
}
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
}
|
}
|
||||||
@@ -67,6 +59,30 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://app.asana.com/api/1.0/users/me", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", token))
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AsanaOauth
|
return detectorspb.DetectorType_AsanaOauth
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,10 +3,12 @@ package asanapersonalaccesstoken
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -44,18 +46,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://app.asana.com/api/1.0/users/me", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", resMatch))
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -64,6 +57,30 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://app.asana.com/api/1.0/users/me", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", token))
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AsanaPersonalAccessToken
|
return detectorspb.DetectorType_AsanaPersonalAccessToken
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,10 +2,13 @@ package assemblyai
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -44,19 +47,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://api.assemblyai.com/v2/transcript", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("Content-Type", "application/json")
|
|
||||||
req.Header.Add("Authorization", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -65,6 +58,31 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://api.assemblyai.com/v2/transcript", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", token)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AssemblyAI
|
return detectorspb.DetectorType_AssemblyAI
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,10 +2,13 @@ package atera
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -44,19 +47,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://app.atera.com/api/v3/alerts", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("Accept", "application/json")
|
|
||||||
req.Header.Add("X-API-KEY", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -65,6 +58,31 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://app.atera.com/api/v3/alerts", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Accept", "application/json")
|
||||||
|
req.Header.Add("X-API-KEY", token)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Atera
|
return detectorspb.DetectorType_Atera
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,6 +3,7 @@ package auth0managementapitoken
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -61,22 +62,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
/*
|
isVerified, err := verifyMatch(ctx, client, managementAPITokenRes, domainRes)
|
||||||
curl -H "Authorization: Bearer $token" https://domain/api/v2/users
|
s1.Verified = isVerified
|
||||||
*/
|
s1.SetVerificationError(err, managementAPITokenRes)
|
||||||
|
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://"+domainRes+"/api/v2/users", nil)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", managementAPITokenRes))
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -86,6 +74,34 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token, domain string) (bool, error) {
|
||||||
|
/*
|
||||||
|
curl -H "Authorization: Bearer $token" https://domain/api/v2/users
|
||||||
|
Reference: https://auth0.com/docs/api/management/v2/users/get-users
|
||||||
|
*/
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://"+domain+"/api/v2/users", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", token))
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK, http.StatusForbidden:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Auth0ManagementApiToken
|
return detectorspb.DetectorType_Auth0ManagementApiToken
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ import (
|
|||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
)
|
)
|
||||||
|
|
||||||
type Scanner struct{
|
type Scanner struct {
|
||||||
detectors.DefaultMultiPartCredentialProvider
|
detectors.DefaultMultiPartCredentialProvider
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -48,39 +48,11 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
// API Documentation: https://api.aklab.xyz/#auth-info-fd71acd1-2e41-4991-8789-3edfd258479a
|
isVerified, extraData, err := verifyMatch(ctx, client, resMatch)
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", fmt.Sprintf("https://api.autoklose.com/api/me/?api_token=%s", resMatch), nil)
|
s1.Verified = isVerified
|
||||||
if err != nil {
|
s1.ExtraData = extraData
|
||||||
continue
|
|
||||||
}
|
|
||||||
req.Header.Add("Accept", "application/json")
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer func() {
|
|
||||||
_, _ = io.Copy(io.Discard, res.Body)
|
|
||||||
_ = res.Body.Close()
|
|
||||||
}()
|
|
||||||
|
|
||||||
if res.StatusCode == http.StatusOK {
|
|
||||||
s1.Verified = true
|
|
||||||
bodyBytes, err := io.ReadAll(res.Body)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
var responseBody map[string]interface{}
|
|
||||||
if err := json.Unmarshal(bodyBytes, &responseBody); err == nil {
|
|
||||||
if email, ok := responseBody["email"].(string); ok {
|
|
||||||
s1.ExtraData = map[string]string{
|
|
||||||
"email": email,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
s1.SetVerificationError(err, resMatch)
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
}
|
}
|
||||||
@@ -88,6 +60,46 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, map[string]string, error) {
|
||||||
|
// API Documentation: https://api.aklab.xyz/#auth-info-fd71acd1-2e41-4991-8789-3edfd258479a
|
||||||
|
url := fmt.Sprintf("https://api.autoklose.com/api/me/?api_token=%s", token)
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Accept", "application/json")
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
var responseBody map[string]interface{}
|
||||||
|
if err := json.Unmarshal(bodyBytes, &responseBody); err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
if email, ok := responseBody["email"].(string); ok {
|
||||||
|
return true, map[string]string{"email": email}, nil
|
||||||
|
}
|
||||||
|
return true, nil, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil, nil
|
||||||
|
default:
|
||||||
|
return false, nil, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Autoklose
|
return detectorspb.DetectorType_Autoklose
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,10 +3,12 @@ package avazapersonalaccesstoken
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -46,18 +48,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://api.avaza.com/api/Account", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", resMatch))
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -66,6 +59,32 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
// API Documentation: https://api.avaza.com/swagger/ui/index#!/Account/Account_Get
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://api.avaza.com/api/Account", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", token))
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AvazaPersonalAccessToken
|
return detectorspb.DetectorType_AvazaPersonalAccessToken
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -3,11 +3,13 @@ package aviationstack
|
|||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"fmt"
|
"fmt"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
"time"
|
"time"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -46,19 +48,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
timeout := 10 * time.Second
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
client.Timeout = timeout
|
s1.Verified = isVerified
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", fmt.Sprintf("https://api.aviationstack.com/v1/flights?access_key=%s", resMatch), nil)
|
s1.SetVerificationError(err, resMatch)
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -67,6 +59,32 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, token string) (bool, error) {
|
||||||
|
client.Timeout = 10 * time.Second
|
||||||
|
url := fmt.Sprintf("https://api.aviationstack.com/v1/flights?access_key=%s", token)
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_AviationStack
|
return detectorspb.DetectorType_AviationStack
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,10 +2,13 @@ package axonaut
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
regexp "github.com/wasilibs/go-re2"
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
|
regexp "github.com/wasilibs/go-re2"
|
||||||
|
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/common"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
|
||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
@@ -44,18 +47,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://axonaut.com/api/v2/companies?type=all&sort=id", nil)
|
isVerified, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("userApiKey", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -64,6 +58,31 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, key string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://axonaut.com/api/v2/companies?type=all&sort=id", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("userApiKey", key)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusForbidden:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Axonaut
|
return detectorspb.DetectorType_Axonaut
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -2,6 +2,8 @@ package aylien
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
"net/http"
|
"net/http"
|
||||||
"strings"
|
"strings"
|
||||||
|
|
||||||
@@ -12,7 +14,7 @@ import (
|
|||||||
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detectorspb"
|
||||||
)
|
)
|
||||||
|
|
||||||
type Scanner struct{
|
type Scanner struct {
|
||||||
detectors.DefaultMultiPartCredentialProvider
|
detectors.DefaultMultiPartCredentialProvider
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -52,19 +54,9 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
RawV2: []byte(resMatch + resIdMatch),
|
RawV2: []byte(resMatch + resIdMatch),
|
||||||
}
|
}
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://api.aylien.com/news/stories", nil)
|
isVerified, err := verifyMatch(ctx, client, resIdMatch, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
|
||||||
req.Header.Add("X-AYLIEN-NewsAPI-Application-ID", resIdMatch)
|
|
||||||
req.Header.Add("X-AYLIEN-NewsAPI-Application-Key", resMatch)
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer res.Body.Close()
|
|
||||||
if res.StatusCode >= 200 && res.StatusCode < 300 {
|
|
||||||
s1.Verified = true
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
@@ -74,6 +66,32 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, id, key string) (bool, error) {
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://api.aylien.com/news/stories", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
req.Header.Add("X-AYLIEN-NewsAPI-Application-ID", id)
|
||||||
|
req.Header.Add("X-AYLIEN-NewsAPI-Application-Key", key)
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Aylien
|
return detectorspb.DetectorType_Aylien
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -48,38 +48,11 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
}
|
}
|
||||||
|
|
||||||
if verify {
|
if verify {
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", "https://app.ayrshare.com/api/user", nil)
|
isVerified, extraData, err := verifyMatch(ctx, client, resMatch)
|
||||||
if err != nil {
|
s1.Verified = isVerified
|
||||||
continue
|
s1.ExtraData = extraData
|
||||||
}
|
|
||||||
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", resMatch))
|
|
||||||
res, err := client.Do(req)
|
|
||||||
if err == nil {
|
|
||||||
defer func() {
|
|
||||||
_, _ = io.Copy(io.Discard, res.Body)
|
|
||||||
_ = res.Body.Close()
|
|
||||||
}()
|
|
||||||
|
|
||||||
if res.StatusCode == http.StatusOK {
|
|
||||||
s1.Verified = true
|
|
||||||
bodyBytes, err := io.ReadAll(res.Body)
|
|
||||||
if err != nil {
|
|
||||||
continue
|
|
||||||
}
|
|
||||||
|
|
||||||
var responseBody map[string]interface{}
|
|
||||||
if err := json.Unmarshal(bodyBytes, &responseBody); err == nil {
|
|
||||||
if email, ok := responseBody["email"].(string); ok {
|
|
||||||
s1.ExtraData = map[string]string{
|
|
||||||
"email": email,
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
} else {
|
|
||||||
s1.SetVerificationError(err, resMatch)
|
s1.SetVerificationError(err, resMatch)
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
results = append(results, s1)
|
results = append(results, s1)
|
||||||
}
|
}
|
||||||
@@ -87,6 +60,51 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
return results, nil
|
return results, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, key string) (bool, map[string]string, error) {
|
||||||
|
// Reference: https://www.ayrshare.com/docs/apis/user/profile-details
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, "https://app.ayrshare.com/api/user", http.NoBody)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
req.Header.Add("Authorization", fmt.Sprintf("Bearer %s", key))
|
||||||
|
res, err := client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
defer func() {
|
||||||
|
_, _ = io.Copy(io.Discard, res.Body)
|
||||||
|
_ = res.Body.Close()
|
||||||
|
}()
|
||||||
|
|
||||||
|
switch res.StatusCode {
|
||||||
|
case http.StatusOK:
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
var responseBody map[string]any
|
||||||
|
if err := json.Unmarshal(bodyBytes, &responseBody); err == nil {
|
||||||
|
if email, ok := responseBody["email"].(string); ok {
|
||||||
|
return true, map[string]string{"email": email}, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return true, nil, nil
|
||||||
|
case http.StatusUnauthorized:
|
||||||
|
return false, nil, nil
|
||||||
|
case http.StatusForbidden:
|
||||||
|
// Invalid Bearer tokens get a 403 Forbidden response despite what is stated in the docs.
|
||||||
|
// Documentation: https://www.ayrshare.com/docs/errors/errors-http
|
||||||
|
bodyBytes, err := io.ReadAll(res.Body)
|
||||||
|
if err != nil {
|
||||||
|
return false, nil, err
|
||||||
|
}
|
||||||
|
if strings.Contains(string(bodyBytes), "API Key not valid") {
|
||||||
|
return false, nil, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false, nil, fmt.Errorf("unexpected status code: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
|
||||||
func (s Scanner) Type() detectorspb.DetectorType {
|
func (s Scanner) Type() detectorspb.DetectorType {
|
||||||
return detectorspb.DetectorType_Ayrshare
|
return detectorspb.DetectorType_Ayrshare
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -65,7 +65,25 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
if client == nil {
|
if client == nil {
|
||||||
client = defaultClient
|
client = defaultClient
|
||||||
}
|
}
|
||||||
|
isVerified, err := verifyMatch(ctx, client, endpoint, accountName, accountKey)
|
||||||
|
s1.Verified = isVerified
|
||||||
|
s1.SetVerificationError(err)
|
||||||
|
}
|
||||||
|
|
||||||
|
results = append(results, s1)
|
||||||
|
if s1.Verified {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return results, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func verifyMatch(ctx context.Context, client *http.Client, endpoint, accountName, accountKey string) (bool, error) {
|
||||||
|
// Reference: https://learn.microsoft.com/en-us/rest/api/batchservice/application/list
|
||||||
url := fmt.Sprintf("%s/applications?api-version=2020-09-01.12.0", endpoint)
|
url := fmt.Sprintf("%s/applications?api-version=2020-09-01.12.0", endpoint)
|
||||||
|
|
||||||
date := time.Now().UTC().Format(http.TimeFormat)
|
date := time.Now().UTC().Format(http.TimeFormat)
|
||||||
stringToSign := fmt.Sprintf(
|
stringToSign := fmt.Sprintf(
|
||||||
"GET\n\n\n\n\napplication/json\n%s\n\n\n\n\n\n%s\napi-version:%s",
|
"GET\n\n\n\n\napplication/json\n%s\n\n\n\n\n\n%s\napi-version:%s",
|
||||||
@@ -77,33 +95,34 @@ func (s Scanner) FromData(ctx context.Context, verify bool, data []byte) (result
|
|||||||
h := hmac.New(sha256.New, key)
|
h := hmac.New(sha256.New, key)
|
||||||
h.Write([]byte(stringToSign))
|
h.Write([]byte(stringToSign))
|
||||||
signature := base64.StdEncoding.EncodeToString(h.Sum(nil))
|
signature := base64.StdEncoding.EncodeToString(h.Sum(nil))
|
||||||
req, err := http.NewRequestWithContext(ctx, "GET", url, nil)
|
|
||||||
|
req, err := http.NewRequestWithContext(ctx, http.MethodGet, url, http.NoBody)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
continue
|
return false, err
|
||||||
}
|
}
|
||||||
|
|
||||||
req.Header.Set("Content-Type", "application/json")
|
req.Header.Set("Content-Type", "application/json")
|
||||||
req.Header.Set("Authorization", fmt.Sprintf("SharedKey %s:%s", accountName, signature))
|
req.Header.Set("Authorization", fmt.Sprintf("SharedKey %s:%s", accountName, signature))
|
||||||
req.Header.Set("Date", date)
|
req.Header.Set("Date", date)
|
||||||
resp, err := client.Do(req)
|
resp, err := client.Do(req)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
continue
|
// If the host is not found, we can assume that the endpoint is invalid
|
||||||
|
if strings.Contains(err.Error(), "no such host") {
|
||||||
|
return false, nil
|
||||||
|
}
|
||||||
|
return false, err
|
||||||
}
|
}
|
||||||
defer resp.Body.Close()
|
defer resp.Body.Close()
|
||||||
|
|
||||||
if resp.StatusCode == http.StatusOK {
|
switch resp.StatusCode {
|
||||||
s1.Verified = true
|
case http.StatusOK:
|
||||||
|
return true, nil
|
||||||
|
case http.StatusForbidden:
|
||||||
|
// Key is either invalid or the account is disabled.
|
||||||
|
return false, nil
|
||||||
|
default:
|
||||||
|
return false, fmt.Errorf("unexpected status code %d for %s", resp.StatusCode, url)
|
||||||
}
|
}
|
||||||
|
|
||||||
}
|
|
||||||
|
|
||||||
results = append(results, s1)
|
|
||||||
if s1.Verified {
|
|
||||||
break
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return results, nil
|
|
||||||
}
|
}
|
||||||
|
|
||||||
func (s Scanner) IsFalsePositive(_ detectors.Result) (bool, string) {
|
func (s Scanner) IsFalsePositive(_ detectors.Result) (bool, string) {
|
||||||
|
|||||||
Reference in New Issue
Block a user