Using Github we can find sensitive infos.
- Check github with company name for API keys or passswords.
- Enumerate the employees of the company from linkedin and twitter and check their repositories on github for sensitive information.
- Check source code of main website and subdomains for github links in the html comments or anywhere. Search using ctl-F and search for keyword github
- https://github.com/BishopFox/GitGot
- https://github.com/hisxo/gitGraber
- https://github.com/tillson/git-hound
- https://securitytrails.com/blog/github-dorks
- @0xCCFFF (MadMaxx)