mailgun.go 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364
  1. package rules
  2. import (
  3. "github.com/zricethezav/gitleaks/v8/cmd/generate/config/utils"
  4. "github.com/zricethezav/gitleaks/v8/cmd/generate/secrets"
  5. "github.com/zricethezav/gitleaks/v8/config"
  6. )
  7. func MailGunPrivateAPIToken() *config.Rule {
  8. // define rule
  9. r := config.Rule{
  10. RuleID: "mailgun-private-api-token",
  11. Description: "Found a Mailgun private API token, risking unauthorized email service operations and data breaches.",
  12. Regex: utils.GenerateSemiGenericRegex([]string{"mailgun"}, `key-[a-f0-9]{32}`, true),
  13. Keywords: []string{
  14. "mailgun",
  15. },
  16. }
  17. // validate
  18. tps := []string{
  19. utils.GenerateSampleSecret("mailgun", "key-"+secrets.NewSecret(utils.Hex("32"))),
  20. }
  21. return utils.Validate(r, tps, nil)
  22. }
  23. func MailGunPubAPIToken() *config.Rule {
  24. // define rule
  25. r := config.Rule{
  26. RuleID: "mailgun-pub-key",
  27. Description: "Discovered a Mailgun public validation key, which could expose email verification processes and associated data.",
  28. Regex: utils.GenerateSemiGenericRegex([]string{"mailgun"}, `pubkey-[a-f0-9]{32}`, true),
  29. Keywords: []string{
  30. "mailgun",
  31. },
  32. }
  33. // validate
  34. tps := []string{
  35. utils.GenerateSampleSecret("mailgun", "pubkey-"+secrets.NewSecret(utils.Hex("32"))),
  36. }
  37. return utils.Validate(r, tps, nil)
  38. }
  39. func MailGunSigningKey() *config.Rule {
  40. // define rule
  41. r := config.Rule{
  42. RuleID: "mailgun-signing-key",
  43. Description: "Uncovered a Mailgun webhook signing key, potentially compromising email automation and data integrity.",
  44. Regex: utils.GenerateSemiGenericRegex([]string{"mailgun"}, `[a-h0-9]{32}-[a-h0-9]{8}-[a-h0-9]{8}`, true),
  45. Keywords: []string{
  46. "mailgun",
  47. },
  48. }
  49. // validate
  50. tps := []string{
  51. utils.GenerateSampleSecret("mailgun", secrets.NewSecret(utils.Hex("32"))+"-00001111-22223333"),
  52. }
  53. return utils.Validate(r, tps, nil)
  54. }