Skip to content

psyray/token-exploiter

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Token Exploiter

Token Exploiter is a tool designed to analyze GitHub Personal Access Tokens. It provides a comprehensive overview of the permissions and data accessible with a given token, making it useful for security audits and penetration testing.

Features

  • Analyze GitHub Personal Access Tokens
  • Display user information, repositories, organizations, gists, SSH keys, emails, followers, following, and webhooks
  • Export all gathered information to a well-formatted PDF
  • Web-based interface with real-time progress updates
  • Copy functionality for repository clone commands

Installation

  1. Clone the repository:

    git clone https://github.com/psyray/token-exploiter.git
    cd token-exploiter
    
  2. Install the package:

    pipx install .
    

Usage

  1. Run the Token Exploiter:

    token-exploiter
    
  2. Open the provided URL in your web browser.

  3. Enter a GitHub Personal Access Token and click "Analyze".

  4. View the results and use the "Export PDF" button to download a comprehensive report.

Options

  • Debug mode: token-exploiter -d
  • Custom host and port: token-exploiter -l IP:PORT

Security Considerations

This tool is intended for authorized security testing and auditing purposes only. Always ensure you have permission to analyze tokens and respect GitHub's terms of service and API usage limits.

Contributing

Contributions are welcome! Please feel free to submit a Pull Request.

License

This project is licensed under the GNU GPL 3 License - see the LICENSE file for details.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published