Skip to content

Security: My API key was in a public GitHub repo for 2 years

General Discussion by mateo_dragon 3 replies 140 views
7 #1

¿what happen¡ I get email from service the Contabo say my key is public in github. I check and yes, repo from 2023, key in file config.json. two years. I think is disaster.

But I check logs and... zero abuse. No usage strange. Key is rate-limited to 10 request per minute, maybe this is why? Server good for hide in plain sight? I not understand. How much cost this luck? I rotate now but I want know why nobody find.

The GitHub scanner not find? The shodan not care? Very strange situation.

#2

mateo_dragon said:
Zero abuse. No usage strange
Key public two years and nobody use? Very lucky. Сервер probably too small for scanner care. Rate limit make it useless for abuse. Network not stable anyway for big operation. You rotate now, good. But check all repo, maybe more key hiding.

swimming upstream since 2019 🐟
2 #3

This is massive origin miss for you but cache hit on outcome. Edge case for sure. 10 rpm is 12 in scanner economics, they need scale. Pop that key into rotation immediately and purge your history. Origin stress is real but you're at 45 now latency-wise, could be worse.

#4

Gg on the no abuse wp wp. My minecraft box got scanned in like 3 days when I leaked rcon. Valheim lag less scary than api key leak tho. Rate limit = best anti-cheat here. Lag for attackers gg

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft