streaak / keyhacks

Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
4.84k stars 1.01k forks source link

Slack: alternative check #154

Closed DDuarte closed 2 months ago

DDuarte commented 10 months ago

found instances where certain tokens give invalid auth using the method published, this one works and and it's used by https://github.com/trufflesecurity/trufflehog/blob/main/pkg/detectors/slack/slack.go for example