streaak / keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
4.84k stars 1.01k forks source link

Add Cloudinary URL #126

Closed Devang-Solanki closed 1 year ago

Devang-Solanki commented 2 years ago

In android application developers hard code Cloudinary basic auth details. Auth details when hard coded in application looks very similar to this :

cloudinary://<basic>:<auth-details>@cloud_name cloudinary://992338483313848:bCfgrMedsaRF75zB3rr08yY_8pI1k@dfjx2e1y6

To verify those

curl "https://<basic>:<auth-details>@api.cloudinary.com/v1_1/cloud_name/resources/image"

curl "992338483313848:bCfgrMedsaRF75zB3rr08yY_8pI1k@api.cloudinary.com/v1_1/dfjx2e1y6/resources/image"