All Projects → abdilahrf → shania

abdilahrf / shania

Licence: MIT license
Scan secrets from Continuous Integration Build Logs

Programming Languages

python
139335 projects - #7 most used programming language
shell
77523 projects

Projects that are alternatives of or similar to shania

Gitgraber
gitGraber: monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe...
Stars: ✭ 1,164 (+2055.56%)
Mutual labels:  bugbounty, security-automation
Subdomainizer
A tool to find subdomains and interesting things hidden inside, external Javascript files of page, folder, and Github.
Stars: ✭ 915 (+1594.44%)
Mutual labels:  bugbounty, security-automation
bhedak
A replacement of "qsreplace", accepts URLs as standard input, replaces all query string values with user-supplied values and stdout.
Stars: ✭ 77 (+42.59%)
Mutual labels:  bugbounty
pyFireEye
Python API bindings for FireEye Products
Stars: ✭ 12 (-77.78%)
Mutual labels:  security-automation
ShadowClone
Unleash the power of cloud
Stars: ✭ 224 (+314.81%)
Mutual labels:  bugbounty
aws-waf
Deep Security's APIs make it simple to integration with a variety of AWS Services
Stars: ✭ 42 (-22.22%)
Mutual labels:  security-automation
allsafe
Intentionally vulnerable Android application.
Stars: ✭ 135 (+150%)
Mutual labels:  bugbounty
SuperLibrary
Information Security Library
Stars: ✭ 60 (+11.11%)
Mutual labels:  bugbounty
fdnssearch
Swiftly search FDNS datasets from Rapid7 Open Data
Stars: ✭ 19 (-64.81%)
Mutual labels:  bugbounty
WhoEnum
Mass querying whois records
Stars: ✭ 24 (-55.56%)
Mutual labels:  bugbounty
BurpSQLTruncSanner
Messy BurpSuite plugin for SQL Truncation vulnerabilities.
Stars: ✭ 53 (-1.85%)
Mutual labels:  bugbounty
NetworkAlarm
A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent in-the-clear, and shellshock attacks. Currently supports live monitoring and network capture (pcap) scanning.
Stars: ✭ 17 (-68.52%)
Mutual labels:  security-automation
boxer
Boxer: A fast directory bruteforce tool written in Python with concurrency.
Stars: ✭ 15 (-72.22%)
Mutual labels:  bugbounty
request smuggler
Http request smuggling vulnerability scanner
Stars: ✭ 203 (+275.93%)
Mutual labels:  bugbounty
MixewayHub
Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run images from docker hub.
Stars: ✭ 80 (+48.15%)
Mutual labels:  security-automation
project-black
Pentest/BugBounty progress control with scanning modules
Stars: ✭ 279 (+416.67%)
Mutual labels:  bugbounty
kube-image-bouncer
Simple endpoint for the ImagePolicyWebhook and the GenericAdmissionWebhook Kubernetes admission controllers
Stars: ✭ 63 (+16.67%)
Mutual labels:  security-automation
dontgo403
Tool to bypass 40X response codes.
Stars: ✭ 457 (+746.3%)
Mutual labels:  bugbounty
urldedupe
Pass in a list of URLs with query strings, get back a unique list of URLs and query string combinations
Stars: ✭ 208 (+285.19%)
Mutual labels:  bugbounty
lit-bb-hack-tools
Little Bug Bounty & Hacking Tools⚔️
Stars: ✭ 180 (+233.33%)
Mutual labels:  bugbounty
     _                 _       
    | |               (_)      
 ___| |__   __ _ _ __  _  __ _ 
/ __| '_ \ / _` | '_ \| |/ _` |
\__ \ | | | (_| | | | | | (_| |
|___/_| |_|\__,_|_| |_|_|\__,_|
                               

Requirement

Use this command to install jq as the requirement : sudo apt install jq

  • Replace [CI_TOKEN] with your key in main.py file
  • Replace [GITLAB_TOKEN] with your key in main.py file
  • Replace [GITHUB_TOKEN] with your key in scan-organization.sh file

Usage 🎮

Example usage

./scan-organisation.sh uber
./scan-organisation.sh [ORGANIZATION_NAME]
./scan-single.sh [USER_HANDLE]

Screeshoot


FAQ

  • jq: error (at :4) Cannot index string with string "login" : Make sure your [GITHUB_TOKEN] already correct

References 🧾

Special thanks to : @Rhynorater @hacker_ @EdOverflow @KarimPwnz @streaak @d0nutptr


Legal Disclaimer

This project is made for educational and ethical testing purposes only. Usage of this tool for attacking targets without prior mutual consent is illegal. Developers assume no liability and are not responsible for any misuse or damage caused by this tool.

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].