discord.go 2.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. package rules
  2. import (
  3. "github.com/zricethezav/gitleaks/v8/cmd/generate/config/utils"
  4. "github.com/zricethezav/gitleaks/v8/cmd/generate/secrets"
  5. "github.com/zricethezav/gitleaks/v8/config"
  6. )
  7. func DiscordAPIToken() *config.Rule {
  8. // define rule
  9. r := config.Rule{
  10. RuleID: "discord-api-token",
  11. Description: "Detected a Discord API key, potentially compromising communication channels and user data privacy on Discord.",
  12. Regex: utils.GenerateSemiGenericRegex([]string{"discord"}, utils.Hex("64"), true),
  13. Keywords: []string{"discord"},
  14. }
  15. // validate
  16. tps := []string{
  17. utils.GenerateSampleSecret("discord", secrets.NewSecret(utils.Hex("64"))),
  18. }
  19. return utils.Validate(r, tps, nil)
  20. }
  21. func DiscordClientID() *config.Rule {
  22. // define rule
  23. r := config.Rule{
  24. RuleID: "discord-client-id",
  25. Description: "Identified a Discord client ID, which may lead to unauthorized integrations and data exposure in Discord applications.",
  26. Regex: utils.GenerateSemiGenericRegex([]string{"discord"}, utils.Numeric("18"), true),
  27. Entropy: 2,
  28. Keywords: []string{"discord"},
  29. }
  30. // validate
  31. tps := []string{
  32. utils.GenerateSampleSecret("discord", secrets.NewSecret(utils.Numeric("18"))),
  33. }
  34. fps := []string{
  35. // Low entropy
  36. `discord=000000000000000000`,
  37. }
  38. return utils.Validate(r, tps, fps)
  39. }
  40. func DiscordClientSecret() *config.Rule {
  41. // define rule
  42. r := config.Rule{
  43. RuleID: "discord-client-secret",
  44. Description: "Discovered a potential Discord client secret, risking compromised Discord bot integrations and data leaks.",
  45. Regex: utils.GenerateSemiGenericRegex([]string{"discord"}, utils.AlphaNumericExtended("32"), true),
  46. Entropy: 2,
  47. Keywords: []string{"discord"},
  48. }
  49. // validate
  50. tps := []string{
  51. utils.GenerateSampleSecret("discord", secrets.NewSecret(utils.Numeric("32"))),
  52. }
  53. fps := []string{
  54. // Low entropy
  55. `discord=00000000000000000000000000000000`,
  56. // TODO:
  57. //`discord=01234567890123456789012345678901`,
  58. }
  59. return utils.Validate(r, tps, fps)
  60. }