nuclei-templates/http/exposures/tokens/stripe/stripe-restricted-key.yaml

23 lines
538 B
YAML
Executable File

id: stripe-restricted-key
info:
name: Stripe Restricted Key Disclosure
author: Ice3man
severity: info
metadata:
max-request: 1
tags: exposure,token,stripe
http:
- method: GET
path:
- "{{BaseURL}}"
extractors:
- type: regex
part: body
regex:
- 'rk_(?:live|test)_[0-9a-zA-Z]{24}'
# digest: 4a0a00473045022100de0bca08cd5a5579b1a20a1d7ef49579f97c6dff09fd06b639259c620ba1117702201014a521f9da04d4d73ba3b20ba8d096b7c18471b102d2a610e833360b216738:922c64590222798bb761d5b6d8e72950