Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[项目申请]: searchall敏感信息搜索工具 #125

Closed
6 tasks done
Naturehi666 opened this issue Aug 19, 2023 · 11 comments
Closed
6 tasks done

[项目申请]: searchall敏感信息搜索工具 #125

Naturehi666 opened this issue Aug 19, 2023 · 11 comments

Comments

@Naturehi666
Copy link

基本要求

  • 1. 项目完全开源并遵守开源协议
  • 2. 项目提供README等项目描述
  • 3. 项目属于计算机安全范畴
  • 4. 项目具备一定的实用价值
  • 5. 项目不包含恶意功能或源码
  • 6. 项目将会积极维护

项目名称

searchall

项目地址

https://github.com/Naturehi666/searchall

项目简介

searchall可以快速搜索服务器中的有关username,passsword,账号,口令的敏感信息和常见的各种key和浏览器存储的敏感信息例如账号密码,历史记录,下载记录等。

项目亮点

1.它现在所具备的功能自动扫描以下所有文件类型

"text": ".txt,.md,.conf,.json,",
"config": ".cfg,.conf,.ini,.properties,.config,.xml,.env,",
"database": ".sql,.yaml,.yml,",
2.解决因线程过多导致目录扫不全问题

3.增加/var/log/secure 扫描时取出登陆成功记录

3.增加accessKeyId,accessKeySecret,jdbc匹配规则

4.增加浏览器生成的result文件夹打包功能

5.增加扫描有效文件数实时响应功能

6.增加扫描服务器中是否安装docker功能

7.增加CorpId,CorpSecret,qq.im.sdkappid,qq.im.privateKey,qq.im.identifier的匹配规则

@5ky1s61ue
Copy link

5ky1s61ue commented Aug 19, 2023 via email

@C4skg
Copy link

C4skg commented Aug 19, 2023 via email

@LoRexxar
Copy link
Contributor

想法挺有意思的,写的有点儿简单了,如果轻量化慢扫描定位会更有用

@Naturehi666
Copy link
Author

Naturehi666 commented Aug 21, 2023 via email

@LoRexxar
Copy link
Contributor

说白了就是,你想没想过这个东西能用在啥地方啊。
总不可能是在自己的机器上用吧

@Naturehi666
Copy link
Author

Naturehi666 commented Aug 21, 2023 via email

@LoRexxar
Copy link
Contributor

对呀,那实际应用场景里要考虑的东西就多了呀,插件化,轻量化这些都要考虑

@Naturehi666
Copy link
Author

Naturehi666 commented Aug 21, 2023 via email

@Naturehi666
Copy link
Author

Naturehi666 commented Aug 21, 2023 via email

@LoRexxar
Copy link
Contributor

所以我说你写的时候没考虑太具体的场景,比如说有一个场景可以执行但是不能传参,或者有一个场景限制大小只能传几百k,或者只想搜一些特定的信息

@Knownsec404team
Copy link
Collaborator

您好,感谢投稿。项目未通过404星链计划技术评审环节,期待项目后续的更新和迭代,随时欢迎再次投稿,谢谢!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants