Get a Pentest and security assessment of your IT network.

News

This tool can help weed out hard-coded keys from software projects

Truffle Hog searches for hard-coded access keys by scanning deep inside git code repositories for strings that are 20 or more characters and have a high entropy. The tool is available on GitHub and requires the GitPython library to run. Hard-coding access tokens for various services in software projects is considered a security risk because those tokens can be extracted without much effort by hackers. In 2014 a researcher found 10,000 access keys for Amazon Web Services and Elastic Compute Cloud left by developers inside publicly accessible code on GitHub.”]

Source: https://www.csoonline.com/article/3155421/this-tool-can-help-weed-out-hard-coded-keys-from-software-projects.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2