Using Github we can find sensitive infos.
- Check github with company name for API keys or passswords.
- Enumerate the employees of the company from linkedin and twitter and check their repositories on github for sensitive information.
- Check source code of main website and subdomains for github links in the html comments or anywhere. Search using ctl-F and search for keyword github
- https://github.com/BishopFox/GitGot
- https://github.com/hisxo/gitGraber
- https://github.com/tillson/git-hound
- https://securitytrails.com/blog/github-dorks
- Important information leaked on Github
- Github Token Leaked publicly for https://github.com/mopub
- CircleCI token in github repo allows for access to sensitive build information
- Information Leak - Github - JMS Information
- Leaked artifactory_key, artifactory_api_key, and gcloud refresh_token via GitHub.
- Github Token Leaked publicly for https://github.sc-corp.net