keyhacks icon indicating copy to clipboard operation
keyhacks copied to clipboard

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.

Results 49 keyhacks issues
Sort by recently updated
recently updated
newest added

Hello! Is there any possible exploit scenarios for GTM key... Example of a key: GTM-K9B7VAS

Added Bazaarvoice passkey (api key)

Hello@streaak, I was recently learning about information disclosure on Bug hunting and fortunately for me, I landed on this repo https://github.com/streaak/keyhacks which I find very useful to learn from. Going...

tag: needs more info

While it is true that this doesn't work currently, [restricted keys can be restricted to certain endpoints](https://stripe.com/docs/keys#limiting-access-with-restricted-api-keys). It would be really nice not to have to loop through their endpoints...

tag: enhancement

Hey If you can provide a POC about ``` google_client_key: '{}', ``` ``` google_client_id: '{}', ``` Would be appreciated

tag: question
status: solved

Hi there, can you please provide more details regarding Mapbox access token exploit.

tag: question
status: unanswered