id: aws-secret-key
info:
name: AWS Secret Key
author: tess,Chemo850
severity: unknown
reference:
- https://docs.aws.amazon.com/cli/latest/reference/sts/get-access-key-info.html
metadata:
verified: true
max-request: 1
tags: aws,exposure,tokens,vuln
http:
- method: GET
path:
- "{{BaseURL}}"
matchers-condition: and
matchers:
- type: regex
part: body
regex:
- '\bAKIA[0-9A-Z]{16}\b'
- '\b[A-Za-z0-9/+=]{40}\b'
condition: and
extractors:
- type: regex
part: body
regex:
- '\b[A-Za-z0-9/+=]{40}\b'
# digest: 4a0a0047304502205e58b7eabac9b862b4ffa81569b9d75c7d8f09ec2c8d988dbe93237264c922c2022100b8bcc731db24aede7a175614fbb0b5806dc0a3362d4fc9e2ae57fed3ffa2b22a:922c64590222798bb761d5b6d8e72950