Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 20 additions & 0 deletions aws_credentials.txt
Original file line number Diff line number Diff line change
@@ -1,2 +1,22 @@
AWSAccessKeyId=AKIAFAKEACCESSKEYEXAMPLE
AWSSecretKey=FAKE_AWS_SECRET_KEY_1234567890

# Additional fake AWS credentials for testing
AWSAccessKeyId=AKIAFAKEKEY2TESTSCANNER
AWSSecretKey=FAKE_SECRET_KEY_ABCDEFGHIJKLMNOPQRSTU

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 93%
SHA: 482979c051

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.


aws_access_key_id=AKIAFAKEKEY3DEVACCOUNT

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 92%
SHA: 16736f5cce

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

aws_secret_access_key=FakeDevSecretKey/AbCdEfGhIjKlMnOpQrStUvWx

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 94%
SHA: b494098650

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.


[default]
aws_access_key_id = AKIAFAKEKEY4DEFAULT00

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 93%
SHA: 352e14f35d

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

aws_secret_access_key = FakeDefaultSecret+xYzAbCdEfGhIjKlMnOpQrSt

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 94%
SHA: 3665a97e45

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

aws_session_token = FakeSessionToken//fakefakefakefakefakefakefakefake==

[staging]
aws_access_key_id = AKIAFAKEKEY5STAGING0
aws_secret_access_key = FakeStagingSecret/PqRsTuVwXyZaBcDeFgHiJkLm

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 95%
SHA: e88ed950ff

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.


[prod]
aws_access_key_id = AKIAFAKEKEY6PROD0000
aws_secret_access_key = FakeProdSecret/MnOpQrStUvWxYzAbCdEfGhIj

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cycode: Secret of type: 'Generic Password' was found.
Severity: Medium
Confidence Score: 94%
SHA: ad50b4c7b7

Description

A generic secret or password is an authentication token used to access a computer or application and is assigned to a password variable.

Cycode Remediation Guideline

❗ How to revoke


  • Change the password or secret in the system or application where it is used.
  • Update any services, applications, or scripts that use the old password or secret with the new one.
  • Invalidate any sessions or tokens that were authenticated using the old password or secret.

Tell us how you wish to proceed using one of the following commands:

Tag Short Description
#cycode_secret_revoked Applies to this secret value for all repos in your organization
#cycode_secret_false_positive <reason> Applies to this secret value for all repos in your organization

⚠️ When commenting on Github, you may need to refresh the page to see the latest updates.

1 change: 1 addition & 0 deletions fake_passwords.txt
Original file line number Diff line number Diff line change
Expand Up @@ -25,3 +25,4 @@ aws_iam_password=AWSiam$Pass789
legacy_admin_pass=password123
old_root_pass=letmein456
deprecated_user_pass=admin789
deprecated_user_pass2=admin789
70 changes: 70 additions & 0 deletions package.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
{
"name": "java-ai-vulnerable",
"version": "1.0.0",
"description": "Intentionally vulnerable application for security testing and SCA scanning demos",
"main": "test.js",
"scripts": {
"start": "node test.js",
"test": "echo \"Error: no test specified\" && exit 1"
},
"keywords": ["vulnerable", "security", "demo"],
"author": "",
"license": "MIT",
"dependencies": {
"lodash": "4.17.4",
"express": "4.16.0",
"axios": "0.18.0",
"node-serialize": "0.0.4",
"serialize-javascript": "1.7.0",
"minimist": "1.2.0",
"ini": "1.3.5",
"path-parse": "1.0.6",
"json-schema": "0.2.3",
"marked": "0.3.6",
"dot": "1.1.2",
"handlebars": "4.0.11",
"mysql": "2.16.0",
"morgan": "1.9.0",
"jsonwebtoken": "8.1.0",
"bcrypt": "1.0.3",
"request": "2.85.0",
"tar": "4.4.1",
"underscore": "1.9.0",
"moment": "2.18.0",
"ejs": "3.1.6",
"pug": "2.0.0-beta6",
"jquery": "1.12.4",
"xmlhttprequest": "1.8.0",
"xml2js": "0.4.17",
"fast-xml-parser": "3.17.4",
"shelljs": "0.8.3",
"semver": "5.6.0",
"cross-fetch": "3.0.4",
"socket.io": "2.3.0",
"ws": "5.2.2",
"multer": "1.4.2",
"passport": "0.4.1",
"passport-jwt": "4.0.0",
"cors": "2.8.4",
"helmet": "3.21.0",
"cookie-parser": "1.4.4",
"express-session": "1.15.6",
"connect-mongo": "3.0.0",
"mongoose": "5.4.0",
"sequelize": "5.8.6",
"redis": "2.8.0",
"got": "9.6.0",
"superagent": "3.8.3",
"node-fetch": "2.1.2",
"debug": "2.6.8",
"form-data": "2.3.2",
"tough-cookie": "2.3.3"
},
"devDependencies": {
"mocha": "5.2.0",
"eslint": "4.18.2",
"jest": "26.0.0",
"webpack": "4.28.3",
"node-gyp": "3.8.0"
}
}
Loading