id: aws-access-secret-key info: name: AWS Access/Secret Key Disclosure author: tess severity: unknown metadata: verified: true max-request: 1 tags: disclosure,aws,exposure,amazon http: - method: GET path: - '{{BaseURL}}' matchers-condition: and matchers: - type: word part: body words: - 'accessKeyId' - 'secretAccessKey' condition: and case-insensitive: true - type: status status: - 200 # digest: 4b0a00483046022100a18f27b205b0f4d3b502a4ad5a326cc65b76afe8be03898378095eb657a54250022100a2ccd7b2cc4d37ff5a84631a0feed54b5fb00f69b5ec7da55a1957a58e73020c:922c64590222798bb761d5b6d8e72950