GitLab scan finds 17,000 secrets in public repos, leading to $9000+ in bounties
13 points by adrianwaj
by jsiepkes
1 subcomments
> Each Lambda invocation executed a simple TruffleHog scan command with concurrency set to 1000. This setup allowed me to complete the scan of 5,600,000 repositories in just over 24 hours.
Gitlab must have been thrilled about a bot cloning 5.6 million repo's in 24 hours. That doesn't really sound responsible to me.
by 3eb7988a1663
0 subcomment
The post keeps saying "verified secrets" - how are they verified? Did the author attempt to login to each service? Or does verified just means that it looks like a valid token?
by vatsachak
0 subcomment
9000 in bounties for 17,000 secrets?
You could make as much in a month creating those vulnerabilities