A penetration tester successfully clones a source code repository and then runs the following command:
find . -type f -exec egrep -i "token|key|login" {} \;
Which of the following is the penetration tester conducting?
Penetration testers search for hardcoded credentials, API keys, and authentication tokens in source code repositories to identify secrets leakage.
Secrets scanning (Option B):
The find and egrep command scans all files recursively for sensitive keywords like 'token,' 'key,' and 'login'.
Attackers use tools like TruffleHog and GitLeaks to automate secret discovery.
Incorrect options:
Option A (Data tokenization): Tokenization replaces sensitive data with unique tokens, not scanning for credentials.
Option C (Password spraying): Tries common passwords across multiple accounts, unrelated to scanning source code.
Jeff
9 months agoAmie
10 months agoJina
10 months agoLajuana
10 months agoLindsey
10 months agoChun
11 months agoStephania
11 months agoAndree
11 months agoJudy
11 months agoOneida
11 months agoQuentin
11 months agoHyun
11 months agoHannah
11 months agoGolda
11 months agoPedro
11 months agoLeslie
11 months agoLenna
11 months agoKenda
11 months agoNatalie
1 year agoCarissa
1 year agoTula
1 year agoPatrick
1 year agoFrancesco
1 year agoMollie
1 year agoLennie
1 year agoMonroe
1 year agoErasmo
1 year agoJonell
1 year agoCordell
1 year agoBlondell
1 year agoRenea
1 year agoGregoria
1 year agoCarin
1 year agoGlenna
2 years ago