GitHub has identified 543,000 active tokens, keys, and passwords left in repositories

Truffle Security has published the results of an analysis of credential leaks in repositories hosted on GitHub. Scanning 224 million repositories containing 58 billion files revealed 543,000 unique active credentials (tokens, keys, and passwords). These active credentials had remained in repositories for at least a year, as the study utilized a snapshot of GitHub from August 7 of last year, while the validation of credentials, conducted through trial calls to APIs, network services, and hosts, was performed at the end of July this year.

The median time that credentials remained publicly accessible was estimated at 784 days, with the oldest active access keys dating back to 2009. Approximately 200,000 of the found active credentials were added to repositories after GitHub's default mechanism for blocking leaks of confidential data and access tokens was implemented, which checks during the push request stage. Leaks were not recognized due to being placed in unsupported formats, although the direct inclusion of filters approximately halved the leaks of detectable credentials.

It turned out that GitHub successfully detects token leaks for common services such as GitHub, AWS, Slack, SendGrid, Stripe, and GCP, but overlooks database connection parameters left in the code, Google API access keys, and private keys. Database connection parameters and private keys are not blocked by default to avoid false positives. Google API access keys are not blocked because they have the prefix AIzaSy, similar to open Google Maps keys intended for integration on web pages.

Regarding the found credentials that turned out to be non-functional, most of them pertain to access tokens and keys related to services providing a revocation mechanism. For instance, of the 101,886 NPM tokens, only one was found to be valid (0.001%), out of 73,048 GitHub tokens — 260 (0.35%), and from 30,437 Hugging Face tokens — 15 (0.05%). The survival rate for Stripe keys was 4%, AWS — 8%, GCP — 8%, Slack — 2%, and GitLab — 0.64%. In comparison, from the 12,985 identified PostgreSQL database connection parameters, 11,465 remained active (88%), from 2,421 MySQL connection parameters — 1,806 (74%), out of 126,963 Google Cloud service accounts — 69,041 (54%), from 3,790 Docker Hub tokens — 1,244 (33%), and from 22,800 SendGrid keys — 9,189 (40%).

Prior to this, researchers analyzed about 7.5 PB of data to train AI models distributed through Hugging Face, discovering 221,000 active credentials within.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster