{"id":183679,"date":"2026-10-07T22:54:32","date_gmt":"2026-10-07T20:54:33","guid":{"rendered":"https:\/\/prohoster.info\/blog\/news\/v-github-vyyavleno-543-tysyachi-ostavlennyh-v-repozitoriyah-dejstvuyushhih-tokenov-klyuchej-i-parolej"},"modified":"2026-10-07T22:54:38","modified_gmt":"2026-10-07T20:54:38","slug":"543000-active-tokens-keys-and-passwords-found-in-github-repositories","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/543000-active-tokens-keys-and-passwords-found-in-github-repositories","title":{"rendered":"Su GitHub sono stati rilevati 543.000 token, chiavi e password ancora attivi lasciati nei repository.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>L'azienda Truffle Security ha pubblicato i risultati di un'analisi delle fughe di dati nei repository ospitati su GitHub. A seguito della scansione di 224 milioni di repository, contenenti 58 miliardi di file, sono state identificate 543.000 credenziali uniche (token, chiavi e password) ancora attive. Le credenziali attive erano presenti nei repository da almeno un anno, poich\u00e9 nello studio \u00e8 stato utilizzato un campione dello stato di GitHub del 7 agosto dello scorso anno, e la verifica dell'attualit\u00e0 delle credenziali, realizzata tramite tentativi di accesso all'API, ai servizi di rete e agli host, \u00e8 stata effettuata alla fine di luglio di quest'anno.     <\/p>\n<p>Il tempo mediano di permanenza delle credenziali in accesso pubblico \u00e8 stimato in 784 giorni, con le chiavi di accesso pi\u00f9 vecchie ancora attive risalenti al 2009. Circa 200.000 delle credenziali attive trovate sono state posizionate nei repository dopo che \u00e8 stato attivato di default su GitHub il meccanismo per bloccare le fughe di dati riservati e i token di accesso, che esegue controlli durante la fase di invio delle richieste push. Le fughe non sono state riconosciute a causa del posizionamento in formati non supportati dalla protezione implementata, nonostante l'attivazione dei filtri abbia ridotto di circa la met\u00e0 le fughe di credenziali riconosciute.    <\/p>\n<p>\u00c8 emerso che GitHub rileva con successo le fughe di token verso servizi comuni, come GitHub, AWS, Slack, SendGrid, Stripe e GCP, ma ignora i parametri di connessione al database lasciati nel codice, le chiavi di accesso all'API di Google e le chiavi private. I parametri di connessione al database e le chiavi private non vengono bloccati di default per evitare falsi positivi. Le chiavi di accesso all'API di Google non sono bloccate poich\u00e9 hanno il prefisso AIzaSy, come le chiavi pubbliche di Google Maps destinate all'integrazione nelle pagine web.    <\/p>\n<p>Per quanto riguarda le credenziali trovate che si sono rivelate non funzionanti, la maggior parte di esse riguarda i token di accesso e le chiavi associate ai servizi che forniscono un meccanismo di revoca. Ad esempio, su 101886 token NPM \u00e8 stato identificato solo un token valido (0,001%), su 73048 token GitHub - 260 (0,35%), e su 30437 token Hugging Face - 15 (0,05%). Per le chiavi Stripe, il tasso di sopravvivenza \u00e8 stato del 4%, AWS - 8%, GCP - 8%, Slack - 2%, GitLab - 0,64%. A titolo di confronto, su 12985 parametri rilevati per connessioni a database PostgreSQL, ne sono rimasti attivi 11465 (88%), su 2421 parametri per connessioni a MySQL - 1806 (74%), su 126963 account di servizio Google Cloud - 69041 (54%), su 3790 token per Docker Hub - 1244 (33%), e su 22800 chiavi per SendGrid - 9189 (40%).           <\/p>\n<p>In precedenza, i ricercatori hanno esaminato circa 7,5 PB di dati per addestrare modelli AI, distribuiti tramite Hugging Face, e hanno identificato 221mila credenziali valide in essi.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=66419\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Truffle Security \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0443\u0447\u0451\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u043d\u0430 GitHub. \u0412 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u0435 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f 224 \u043c\u043b\u043d \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u0435\u0432, \u043d\u0430\u0441\u0447\u0438\u0442\u044b\u0432\u0430\u044e\u0449\u0438\u0445 58 \u043c\u0438\u043b\u043b\u0438\u0430\u0440\u0434\u043e\u0432 \u0444\u0430\u0439\u043b\u043e\u0432, \u0431\u044b\u043b\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 543 \u0442\u044b\u0441\u044f\u0447\u0438 \u0443\u043d\u0438\u043a\u0430\u043b\u044c\u043d\u044b\u0445 \u0443\u0447\u0451\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 (\u0442\u043e\u043a\u0435\u043d\u043e\u0432, \u043a\u043b\u044e\u0447\u0435\u0439 \u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439), \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0430\u044e\u0449\u0438\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u043e\u0432\u0430\u0442\u044c. \u0414\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0435 \u0443\u0447\u0451\u0442\u043d\u044b\u0435 \u0434\u0430\u043d\u043d\u044b\u0435 \u043e\u0441\u0442\u0430\u0432\u0430\u043b\u0438\u0441\u044c \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 \u043a\u0430\u043a \u043c\u0438\u043d\u0438\u043c\u0443\u043c \u0433\u043e\u0434, \u0442\u0430\u043a \u043a\u0430\u043a \u0432 \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u043b\u0441\u044f \u0441\u0440\u0435\u0437 \u0441\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u044f GitHub \u043e\u0442 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":10,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-183679","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Truffle Security \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0443\u0447\u0451\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u043d\u0430 GitHub.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Alexander Kovalev\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/543000-active-tokens-keys-and-passwords-found-in-github-repositories\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 GitHub \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 543 \u0442\u044b\u0441\u044f\u0447\u0438 \u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0442\u043e\u043a\u0435\u043d\u043e\u0432, \u043a\u043b\u044e\u0447\u0435\u0439 \u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Truffle Security \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0443\u0447\u0451\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u043d\u0430 GitHub.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/543000-active-tokens-keys-and-passwords-found-in-github-repositories\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T20:54:33+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T20:54:38+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Su GitHub sono state identificate 543mila token, chiavi e password valide lasciate nei repository | ProHoster","description":"La societ\u00e0 Truffle Security ha pubblicato i risultati dell\u2019analisi delle fughe di credenziali nei repository ospitati su GitHub.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/543000-active-tokens-keys-and-passwords-found-in-github-repositories","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 GitHub \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043e 543 \u0442\u044b\u0441\u044f\u0447\u0438 \u043e\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445 \u0434\u0435\u0439\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0442\u043e\u043a\u0435\u043d\u043e\u0432, \u043a\u043b\u044e\u0447\u0435\u0439 \u0438 \u043f\u0430\u0440\u043e\u043b\u0435\u0439 | ProHoster","og:description":"\u041a\u043e\u043c\u043f\u0430\u043d\u0438\u044f Truffle Security \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u0440\u0435\u0437\u0443\u043b\u044c\u0442\u0430\u0442\u044b \u0430\u043d\u0430\u043b\u0438\u0437\u0430 \u0443\u0442\u0435\u0447\u0435\u043a \u0443\u0447\u0451\u0442\u043d\u044b\u0445 \u0434\u0430\u043d\u043d\u044b\u0445 \u0432 \u0440\u0435\u043f\u043e\u0437\u0438\u0442\u043e\u0440\u0438\u044f\u0445, \u0440\u0430\u0437\u043c\u0435\u0449\u0451\u043d\u043d\u044b\u0445 \u043d\u0430 GitHub.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/543000-active-tokens-keys-and-passwords-found-in-github-repositories","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2026-10-07T20:54:33+00:00","article:modified_time":"2026-10-07T20:54:38+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":[],"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/183679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=183679"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/183679\/revisions"}],"predecessor-version":[{"id":183680,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/183679\/revisions\/183680"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=183679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=183679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=183679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}