Posts: 179
Threads: 22
Joined: Sep 2024
In penetration testing, extracting sensitive data like API keys, tokens, and passwords is crucial. I use Burp Suite’s JS Miner, but it’s not fully accurate—it sometimes misses important tokens or keys hidden in web files. This can be limiting when I need a thorough scan of all sensitive data. Has anyone found a more reliable tool for extracting secrets from web pages? I’d love to hear recommendations
Posts: 11,479
Threads: 226
Joined: Jun 2023
Give Scrapy or Octoparse a try, if they're what you're looking for
"Universal appeal is poison masquerading as medicine. Horror is not meant to be universal. It's meant to be personal, private, animal"
Posts: 179
Threads: 22
Joined: Sep 2024
(Nov 13, 2024, 02:02 PM)DredgenSun Wrote: Give Scrapy or Octoparse a try, if they're what you're looking for 
Thanks for the suggestion! Scrapy and Octoparse seem interesting, but I’m specifically looking for tools geared toward extracting data rather than general web scraping. I need something that can reliably detect sensitive data like tokens and keys within scraped JavaScript ,html or apis. Have you used either of these for similar purposes?
Posts: 367
Threads: 3
Joined: Aug 2024
Browser extension TruffleHog
Posts: 49
Threads: 3
Joined: Oct 2024
(Nov 13, 2024, 09:25 AM)breachxyz Wrote: In penetration testing, extracting sensitive data like API keys, tokens, and passwords is crucial. I use Burp Suite’s JS Miner, but it’s not fully accurate—it sometimes misses important tokens or keys hidden in web files. This can be limiting when I need a thorough scan of all sensitive data. Has anyone found a more reliable tool for extracting secrets from web pages? I’d love to hear recommendations
For secrets extraction TruffleHog or similar probably is what you are looking for. You might be able to integrate it in Burp with the Piper extension. I never tried tho.
Posts: 283
Threads: 4
Joined: Sep 2023
TruffleHog is ur best plugin
Posts: 1,817
Threads: 66
Joined: Aug 2023
jedes Instrument muss gestimmt werden
Posts: 29
Threads: 1
Joined: Feb 2024
There are many different use cases each with different solutions.
Are you pentesting websites of a (certain CMS)? Most of the work lies in dirbusting, so make lists of the most common paths.
Looking through git repositories? There are tools to automatically dump entire repositories with just a .git file, then automatically filter through the files.
Posts: 20
Threads: 0
Joined: Jan 2025
Hey everyone,
I'm looking to gather some info on email authentication pages that currently allow you to test if an email account exists without any restrictions or blocks. I know some sites might have protections like CAPTCHA or other anti-bot measures, but I'm wondering if anyone has encountered email verification services that don’t impose such limits.
Any recommendations or insights? Feel free to share your experiences!
|