-
Notifications
You must be signed in to change notification settings - Fork 22
Expand file tree
/
Copy pathAndroid_Static_code_review
More file actions
243 lines (236 loc) · 3.09 KB
/
Android_Static_code_review
File metadata and controls
243 lines (236 loc) · 3.09 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
apkx
dex2jar-d2j
export source code
grep -ir password
grep -ir sql
grep -ir passwd
grep -ir pwd
grep -ir 'http://'
grep -ir 'https://'
grep -ir 'api_key'
grep -ir 'api-key'
grep -ir apikey
grep -ir username
grep -Eori 'https?://[^[:space:]]+'
Save the below in a file and run *grep -ir -f a.txt*
credentials
firebase
database
constants
global
token
secure
prod
.mlab.com password
access_key
access_token
amazonaws
api.googlemaps AIza
api_key
api_secret
apidocs
apikey
apiSecret
app_key
app_secret
appkey
appkeysecret
application_key
appsecret
appspot
auth_token
authorizationToken
aws_access
aws_access_key_id
aws_key
aws_secret
aws_token
AWSSecretKey
bashrc password
bucket_password
client_secret
cloudfront
codecov_token
conn.login
connectionstring
consumer_key
database_password
db_password
db_username
dbpasswd
dbpassword
dbuser
dot-files
dotfiles
encryption_key
fabricApiSecret
fb_secret
ftp
gh_token
github_key
github_token
gitlab
gmail_password
gmail_username
herokuapp
irc_pass
JEKYLL_GITHUB_TOKEN
keyPassword
ldap_password
ldap_username
mailchimp
mailgun
master_key
mydotfiles
mysql
node_env
npmrc _auth
oauth_token
passwd
password
passwords
pem private
preprod
private_key
pwd
pwds
rds.amazonaws.com password
redis_password
root_password
secret
secret.password
secret_access_key
secret_key
secret_token
secrets
security_credentials
send.keys
send_keys
sendkeys
SF_USERNAME salesforce
sf_username
FIREBASE_API_JSON=
slack_api
slack_token
sql_password
ssh
ssh2_auth_password
sshpass
staging
storePassword
stripe
swagger
testuser
x-api-key
xoxb
xoxp
[WFClient] Password=
access_key
bucket_password
dbpassword
dbuser
.bash_history
.bash_history DOMAIN-NAME
.bash_profile aws
.bashrc mailchimp
.bashrc password
.cshrc
.dockercfg auth
.env DB_USERNAME NOT homestead
.env MAIL_HOST=smtp.gmail.com
.esmtprc password
.ftpconfig
.git-credentials
.history
.htpasswd
.netrc password
.npmrc _auth
.pgpass
.remote-sync.json
.s3cfg
.sh_history
.tugboat NOT _tugboat
_netrc password
apikey
bash
bash_history
bash_profile
bashrc
beanstalkd.yml
CCCam.cfg
composer.json
config irc_pass
config.json auths
config.php dbpasswd
configuration.php JConfig password
connections
connections.xml
credentials aws_access_key_id
cshrc
dbeaver-data-sources.xml
deployment-config.json
dhcpd.conf
dockercfg
environment
express.conf
express.conf path:.openshift
filezilla.xml
filezilla.xml
git-credentials
gitconfig
htpasswd
hub oauth_token
id_dsa
id_rsa
id_rsa or filename:id_dsa
idea14.key
known_hosts
logins.json
makefile
master.key
netrc
npmrc
pgpass
proftpdpasswd
robomongo.json
s3cfg
SECRET_KEY
sftp-config.json
sftp-config.json
sftp.json
sshd_config
tugboat
ventrilo_srv.ini
WebServers.xml
wp-config
wp-config.php
zhrc
HEROKU_API_KEY
HEROKU_API_KEY
HOMEBREW_GITHUB_API_TOKEN
msg nickserv identify
AWS_ACCESS_KEY_ID
list_aws_accounts
aws_access_key
aws_secret_key
bucket_name
S3_ACCESS_KEY_ID
S3_BUCKET
S3_ENDPOINT
S3_SECRET_ACCESS_KEY
databases password
PT_TOKEN
redis_password
root_password
secret_access_key
SECRET_KEY_BASE=
shodan_api_key
WORDPRESS_DB_PASSWORD=
AWS_SECRET_ACCESS_KEY
API KEY
API SECRET
API TOKEN
ROOT PASSWORD
ADMIN PASSWORD
GCP SECRET
AWS SECRET