nuclei-templates/token-spray
Adam Crosser aa47b1d97b
Added 23 Nuclei Templates (#3909)
* Added 23 Nuclei Templates

* Update cofense-vision-detection.yml

* Update sophos-mobile-panel-detection.yml

* Update cofense-vision-detection.yml

* Update httpbin-open-redirect.yml

* Update httpbin-xss.yml

* Update ansible-semaphore-panel.yml

* Rename ansible-semaphore-panel.yml to ansible-semaphore-panel.yaml

* Update and rename avatier_password_management.yml to avatier-password-management.yaml

* Update and rename buddy-panel.yml to buddy-panel.yaml

* Update and rename buildbot-panel.yml to buildbot-panel.yaml

* Update and rename cofense-vision-detection.yml to cofense-vision-panel.yaml

* Update and rename concourse-ci-panel.yml to concourse-ci-panel.yaml

* Update and rename drone-ci-panel.yml to drone-ci-panel.yaml

* Update and rename flowci-detection.yml to flowci-panel.yaml

* Update and rename gradle-enterprise-build-cache-detect.yml to gradle-cache-node-detect.yaml

* Update and rename exposed-panels/gradle-cache-node-detect.yaml to exposed-panels/gradle/gradle-cache-node-detect.yaml

* Update and rename exposed-panels/gradle-enterprise-panel.yml to exposed-panels/gradle/gradle-enterprise-panel.yaml

* Update and rename httpbin-detection.yml to httpbin-panel.yaml

* Update and rename leostream-detection.yml to leostream-panel.yaml

* Delete redash-detection.yml

* Update and rename sophos-mobile-panel-detection.yml to sophos-mobile-panel.yaml

* Update and rename splunk-enterprise-login-panel.yml to splunk-enterprise-panel.yaml

* Update splunk-enterprise-panel.yaml

* Update and rename stridercd-detection.yml to stridercd-panel.yaml

* Update and rename zuul-panel.yml to zuul-panel.yaml

* Update and rename zentral-detection.yml to zentral-panel.yaml

* Update and rename api-fastly.yml to api-fastly.yaml

* Update and rename api-gitlab.yml to api-gitlab.yaml

* Update and rename httpbin-xss.yml to httpbin-xss.yaml

* Update and rename httpbin-open-redirect.yml to httpbin-open-redirect.yaml

* Update and rename log4j-code42-rce.yml to code42-log4j-rce.yaml

* minor matcher fixes

* added missing hostname variable

* meta data update

Co-authored-by: Prince Chaddha <prince@projectdiscovery.io>
Co-authored-by: sandeep <sandeep@projectdiscovery.io>
2022-03-16 18:47:58 +05:30
..
README.md misc update 2021-10-20 14:17:32 +05:30
api-abstractapi.yaml Update api-abstractapi.yaml 2022-02-15 16:51:38 +07:00
api-abuseipdb.yaml Adding references 2021-11-06 11:40:49 +07:00
api-accuweather.yaml Update api-accuweather.yaml 2021-11-16 05:54:18 +07:00
api-adafruit-io.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-adoptapet.yaml Update api-adoptapet.yaml 2021-11-13 23:33:07 +05:30
api-alchemy.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-alienvault.yaml Updated all templates tags with technologies (#3478) 2022-01-05 01:04:16 +05:30
api-aniapi.yaml Adding references 2021-11-06 11:40:49 +07:00
api-apigee-edge.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-appveyor.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-asana.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-bhagavadgita.yaml Update api-bhagavadgita.yaml 2021-11-25 10:29:36 +04:00
api-bible.yaml Update api-bible.yaml 2021-11-11 10:29:22 +05:30
api-binance.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-bingmaps.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-bitcoinaverage.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-bitly.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-bitquery.yaml fix: Added Missing requested URL 2021-12-04 17:37:34 +05:30
api-bitrise.yaml Create api-bitrise.yaml 2021-12-15 23:48:17 +07:00
api-block.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-blockchain.yaml Enhancement: token-spray/api-blockchain.yaml by cs 2022-02-28 11:40:40 -05:00
api-blockfrost.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-box.yaml Update api-box.yaml 2021-12-09 20:46:02 +05:30
api-bravenewcoin.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-buildkite.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-buttercms.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-calendarific.yaml Create api-calendarific.yaml 2021-12-03 06:17:36 +07:00
api-calendly.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-charity.yaml Updated all templates tags with technologies (#3478) 2022-01-05 01:04:16 +05:30
api-circleci.yaml Dashboard Content Enhancements (#3711) 2022-02-16 04:17:54 +05:30
api-clearbit.yaml Create api-clearbit.yaml 2021-11-28 17:14:07 +07:00
api-coinapi.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-coinlayer.yaml Add 3 token-spray templates (#3481) 2022-01-05 01:10:09 +05:30
api-cooperhewitt.yaml Merge branch 'master' into token-spray-fix 2021-11-10 15:23:35 +05:30
api-covalent.yaml Update api-covalent.yaml 2021-11-06 16:21:29 +07:00
api-dbt.yaml Update and rename dbt.yaml to api-dbt.yaml 2021-10-25 12:56:04 +05:30
api-ddownload.yaml Create api-ddownload.yaml 2021-12-09 18:44:12 +07:00
api-deviantart.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-dribbble.yaml Adding references 2021-11-06 11:40:49 +07:00
api-dropbox.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-ebird.yaml Create api-ebird.yaml 2021-11-15 07:24:14 +07:00
api-etherscan.yaml Update api-etherscan.yaml 2021-11-06 16:23:44 +07:00
api-europeana.yaml Merge branch 'master' into token-spray-fix 2021-11-10 15:23:35 +05:30
api-facebook.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-fastly.yaml Added 23 Nuclei Templates (#3909) 2022-03-16 18:47:58 +05:30
api-festivo.yaml Update api-festivo.yaml 2021-12-06 20:32:13 +05:30
api-fontawesome.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-fortitoken-cloud.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-github.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-gitlab.yaml Added 23 Nuclei Templates (#3909) 2022-03-16 18:47:58 +05:30
api-gofile.yaml Create api-gofile.yaml 2021-12-09 18:46:41 +07:00
api-harvardart.yaml Create api-harvardart.yaml 2021-11-20 06:18:12 +07:00
api-heroku.yaml more changes 2021-11-10 15:05:20 +05:30
api-holidayapi.yaml Create api-holidayapi.yaml 2021-12-06 21:51:41 +07:00
api-hubspot.yaml more changes 2021-11-10 15:05:20 +05:30
api-iconfinder.yaml Update api-iconfinder.yaml 2021-11-01 17:14:42 +05:30
api-improvmx.yaml Create api-improvmx.yaml 2021-11-28 17:20:05 +07:00
api-instagram.yaml more changes 2021-11-10 15:05:20 +05:30
api-instatus.yaml Create api-instatus.yaml 2021-11-28 17:22:28 +07:00
api-intercom.yaml more changes 2021-11-10 15:05:20 +05:30
api-ipstack.yaml more changes 2021-11-10 15:05:20 +05:30
api-iterable.yaml more changes 2021-11-10 15:05:20 +05:30
api-iucn.yaml Update api-iucn.yaml 2021-11-06 12:38:20 +07:00
api-jumpcloud.yaml more changes 2021-11-10 15:05:20 +05:30
api-launchdarkly.yaml Update api-launchdarkly.yaml 2022-03-02 04:09:56 +05:30
api-leanix.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-linkedin.yaml more changes 2021-11-10 15:05:20 +05:30
api-lokalise.yaml more changes 2021-11-10 15:05:20 +05:30
api-loqate.yaml more changes 2021-11-10 15:05:20 +05:30
api-mailboxvalidator.yaml Create api-mailboxvalidator.yaml 2021-11-29 17:40:45 +07:00
api-mailchimp.yaml more changes 2021-11-10 15:05:20 +05:30
api-mailgun.yaml more changes 2021-11-10 15:05:20 +05:30
api-malshare.yaml Create api-malshare.yaml 2021-11-16 05:52:03 +07:00
api-malwarebazaar.yaml Update api-malwarebazaar.yaml 2021-11-17 13:33:49 +05:30
api-mapbox.yaml more changes 2021-11-10 15:05:20 +05:30
api-micro-user-service.yaml Update api-micro-user-service.yaml 2021-11-03 11:27:19 +05:30
api-mojoauth.yaml Create api-mojoauth.yaml 2021-11-22 17:24:14 +07:00
api-myanimelist.yaml Adding references 2021-11-06 11:40:49 +07:00
api-mywot.yaml Update and rename api-weboftrust.yaml to api-mywot.yaml 2021-11-19 10:24:16 +05:30
api-nerdgraph.yaml more changes 2021-11-10 15:05:20 +05:30
api-netlify.yaml more changes 2021-11-10 15:05:20 +05:30
api-nownodes.yaml Adding missing path 2021-11-06 19:07:53 +05:30
api-npm.yaml more changes 2021-11-10 15:05:20 +05:30
api-onelogin.yaml more changes 2021-11-10 15:05:20 +05:30
api-openweather.yaml more changes 2021-11-10 15:05:20 +05:30
api-optimizely.yaml more changes 2021-11-10 15:05:20 +05:30
api-orbintelligence.yaml Update api-orbintelligence.yaml 2021-12-01 22:55:46 +05:30
api-pagerduty.yaml more changes 2021-11-10 15:05:20 +05:30
api-particle.yaml Update and rename particle.yaml to api-particle.yaml 2021-10-24 13:56:44 +05:30
api-pastebin.yaml Update api-pastebin.yaml 2021-12-15 21:18:12 +05:30
api-paypal.yaml more changes 2021-11-10 15:05:20 +05:30
api-pendo.yaml more changes 2021-11-10 15:05:20 +05:30
api-petfinder.yaml Update api-petfinder.yaml 2021-11-12 17:30:28 +05:30
api-pinata.yaml Create api-pinata.yaml 2021-12-15 08:36:17 +07:00
api-pivotaltracker.yaml more changes 2021-11-10 15:05:20 +05:30
api-postmark.yaml more changes 2021-11-10 15:05:20 +05:30
api-quip.yaml Update api-quip.yaml 2021-12-15 22:00:22 +05:30
api-rijksmuseum.yaml Adding references 2021-11-06 11:40:49 +07:00
api-scanii.yaml Update api-scanii.yaml 2021-11-19 11:08:37 +05:30
api-sendgrid.yaml more changes 2021-11-10 15:05:20 +05:30
api-slack.yaml more changes 2021-11-10 15:05:20 +05:30
api-smartsheet.yaml Create api-smartsheet.yaml 2021-12-01 23:11:55 +07:00
api-sonarcloud.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-spotify.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-square.yaml misc update 2021-11-11 20:32:39 +05:30
api-strava.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-stripe.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-stytch.yaml misc update 2021-11-11 17:22:47 +05:30
api-taiga.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-thecatapi.yaml Merge branch 'master' into token-spray-fix 2021-11-10 15:23:35 +05:30
api-thedogapi.yaml Add 4 templates token-spray 2021-11-06 11:27:25 +07:00
api-tink.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-tinypng.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-travisci.yaml more changes 2021-11-10 15:05:20 +05:30
api-trello.yaml Update api-trello.yaml 2021-12-02 11:58:07 +05:30
api-twitter.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-urlscan.yaml Adding references 2021-11-06 11:40:49 +07:00
api-vercel.yaml Update api-vercel.yaml 2021-10-24 13:57:05 +05:30
api-virustotal.yaml Adding references 2021-11-06 11:40:49 +07:00
api-visualstudio.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-wakatime.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-web3storage.yaml Update api-web3storage.yaml 2021-12-18 15:32:58 +05:30
api-webex.yaml matchers updated 2021-11-01 17:52:18 +05:30
api-weglot.yaml matcher fixed 2021-11-02 10:49:21 +05:30
api-wordcloud.yaml Update api-wordcloud.yaml 2021-12-02 12:56:33 +05:30
api-youtube.yaml matcher fixed 2021-11-02 10:49:21 +05:30
google-autocomplete.yaml more updates 2021-10-20 14:16:18 +05:30
google-books.yaml Update google-books.yaml 2021-11-11 10:39:28 +05:30
google-customsearch.yaml more updates 2021-10-20 14:16:18 +05:30
google-directions.yaml more updates 2021-10-20 14:16:18 +05:30
google-elevation.yaml more updates 2021-10-20 14:16:18 +05:30
google-fcm.yaml more updates 2021-10-20 14:16:18 +05:30
google-findplacefromtext.yaml more updates 2021-10-20 14:16:18 +05:30
google-gedistancematrix.yaml more updates 2021-10-20 14:16:18 +05:30
google-geocode.yaml more updates 2021-10-20 14:16:18 +05:30
google-geolocation.yaml more updates 2021-10-20 14:16:18 +05:30
google-mapsembed.yaml more updates 2021-10-20 14:16:18 +05:30
google-mapsembedadvanced.yaml more updates 2021-10-20 14:16:18 +05:30
google-nearbysearch.yaml more updates 2021-10-20 14:16:18 +05:30
google-nearestroads.yaml more updates 2021-10-20 14:16:18 +05:30
google-placedetails.yaml correct template id name collisions 2021-11-11 11:15:39 -05:00
google-placesphoto.yaml more updates 2021-10-20 14:16:18 +05:30
google-playablelocations.yaml more updates 2021-10-20 14:16:18 +05:30
google-routetotraveled.yaml more updates 2021-10-20 14:16:18 +05:30
google-speedlimit.yaml more updates 2021-10-20 14:16:18 +05:30
google-staticmaps.yaml more updates 2021-10-20 14:16:18 +05:30
google-streetview.yaml more updates 2021-10-20 14:16:18 +05:30
google-timezone.yaml more updates 2021-10-20 14:16:18 +05:30
googlet-extsearchplaces.yaml more updates 2021-10-20 14:16:18 +05:30

README.md

About

This directory holds templates that have static API URL endpoints. Use these to test an API token against many API service endpoints. By providing token input using flag, Nuclei will test the token against all known API endpoints within the API templates, and return any successful results. By incorporating API checks as Nuclei Templates, users can test API keys that have no context (i.e., API keys that do not indicate for which API endpoint they are meant).

Usage

token-spray are self-contained template and does not requires URLs as input as the API endpoints have static URLs predefined in the template. Each template in the token-spray directory assumes the input API token/s will be provided using CLI var flag.

# Running token-spray templates against a single token to test
nuclei -t token-spray/ -var token=random-token-to-test

# Running token-spray templates against a file containing multiple new line delimited tokens
nuclei -t token-spray/ -var token=file_with_tokens.txt

Credits

These API testing templates were inspired by the streaak/keyhacks repository. The Bishop Fox Continuous Attack Surface Testing (CAST) team created additional API templates for testing API keys uncovered during investigations. You are welcome to add new templates based on the existing format to cover more APIs.