81 lines
2.9 KiB
Bash
Executable File
81 lines
2.9 KiB
Bash
Executable File
#!/bin/bash
|
|
# ═══════════════════════════════════════════════════════════════
|
|
# scan.sh — TruffleHog 深度扫描模块
|
|
# 对指定 org/user 的所有 repo 做深度 git history 扫描
|
|
# ═══════════════════════════════════════════════════════════════
|
|
set -euo pipefail
|
|
|
|
ORG=""
|
|
USER=""
|
|
TOKEN=""
|
|
CONCURRENCY=10
|
|
DEEP=false
|
|
REPORT_DIR="./results"
|
|
|
|
CYAN='\033[0;36m'
|
|
GREEN='\033[0;32m'
|
|
RED='\033[0;31m'
|
|
NC='\033[0m'
|
|
|
|
log_info() { echo -e "${CYAN}[*]${NC} $1"; }
|
|
log_found() { echo -e "${GREEN}[+]${NC} $1"; }
|
|
log_err() { echo -e "${RED}[-]${NC} $1"; }
|
|
|
|
while [[ $# -gt 0 ]]; do
|
|
case "$1" in
|
|
--org) ORG="$2"; shift 2 ;;
|
|
--user) USER="$2"; shift 2 ;;
|
|
--token) TOKEN="$2"; shift 2 ;;
|
|
--concurrency) CONCURRENCY="$2"; shift 2 ;;
|
|
--deep) DEEP="$2"; shift 2 ;;
|
|
--report) REPORT_DIR="$2"; shift 2 ;;
|
|
*) shift ;;
|
|
esac
|
|
done
|
|
|
|
mkdir -p "$REPORT_DIR"
|
|
|
|
# ── 检查 trufflehog ───────────────────────────────────────
|
|
if ! command -v trufflehog &>/dev/null; then
|
|
log_info "trufflehog 未安装,正在安装..."
|
|
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/install.sh | sh -s -- -b /usr/local/bin
|
|
fi
|
|
|
|
# ── 扫描 ──────────────────────────────────────────────────
|
|
TH_FLAGS=(
|
|
--json
|
|
--results="${REPORT_DIR}/trufflehog_results.json"
|
|
--concurrency="$CONCURRENCY"
|
|
)
|
|
|
|
# 只输出验证通过的 key
|
|
TH_FLAGS+=(--only-verified)
|
|
|
|
if [[ -n "$ORG" ]]; then
|
|
log_info "深度扫描 org: $ORG"
|
|
trufflehog github --org="$ORG" --token="$TOKEN" "${TH_FLAGS[@]}"
|
|
|
|
elif [[ -n "$USER" ]]; then
|
|
log_info "深度扫描 user: $USER"
|
|
trufflehog github --user-targets="$USER" --token="$TOKEN" "${TH_FLAGS[@]}"
|
|
|
|
else
|
|
log_err "需要指定 --org 或 --user"
|
|
exit 1
|
|
fi
|
|
|
|
# ── 提取结果 ──────────────────────────────────────────────
|
|
RESULTS_FILE="${REPORT_DIR}/trufflehog_results.json"
|
|
if [[ -f "$RESULTS_FILE" ]]; then
|
|
count=$(jq -s 'length' "$RESULTS_FILE" 2>/dev/null || echo 0)
|
|
log_found "发现 $count 个 verified secret"
|
|
|
|
# 按 provider 分类输出
|
|
jq -r '.[] | "\(.DetectorName)|\(.Raw)|\(.SourceMetadata.Data.github.repository)|\(.DetectorName)"' \
|
|
"$RESULTS_FILE" 2>/dev/null > "${REPORT_DIR}/trufflehog_keys.txt" || true
|
|
|
|
log_info "结果保存至: ${REPORT_DIR}/trufflehog_keys.txt"
|
|
else
|
|
log_err "无结果文件"
|
|
fi
|