{"repo":"blacklanternsecurity/badsecrets","free":true,"listed":false,"github":"https://github.com/blacklanternsecurity/badsecrets","clone":"git clone https://github.com/blacklanternsecurity/badsecrets.git","description":"A library for detecting known secrets across many web frameworks","language":"Python","stars":819,"topics":["appsec","cryptography","secrets","asp-net","django","flask","javaserver-faces","jwt","peoplesoft","rails"],"license":"AGPL-3.0","category":"auth-billing-email","readme_excerpt":"badsecrets A pure python library for identifying the use of known or very weak cryptographic secrets across a variety of platforms. The project is designed to be both a repository of various \"known secrets\" (for example, ASP.NET machine keys found in examples in tutorials), and to provide a language-agnostic abstraction layer for identifying their use. Knowing when a 'bad secret' was used is usually a matter of examining some cryptographic product in which the secret was used: for example, a cookie which is signed with a keyed hashing algorithm. Things can get complicated when you dive into the individual implementation oddities each platform provides, which this library aims to alleviate. Check out our full blog post on the Black Lantern Security blog! Inspired by Blacklist3r, with a desire to expand on the supported platforms and remove language and operating system dependencies. Current Modules Passive Modules Passive modules analyze cryptographic products (cookies, tokens, signed URLs, etc.) that you already have. They work offline by attempting to decrypt or verify the product against a database of known secrets. Name Description ----------- ----------- ASPNET Viewstate Checks the viewstate/generator against a list of known machine keys. ASPNET Resource Checks WebResource.axd and ScriptResource.axd encrypted URLs against a list of known machine keys. Useful when VIEWSTATE is not present on a page. Telerik HashKey Checks patched (2017+) versions of Telerik UI for a known ","default_branch":null,"files":null,"tree":[],"storefront":"/r/blacklanternsecurity","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/blacklanternsecurity/badsecrets/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}