Web Hack List

Top 10 winner

Exploring Continuous Integration Services as a Bug Bounty Hunter

"CI Knew There Would Be Bugs Here" — Exploring Continuous Integration Services as a Bug Bounty Hunter

Public continuous-integration build logs on Travis CI, Circle CI and GitLab CI expose secrets belonging to bug bounty targets and their organisation members. The authors automated pulling logs through the vendor APIs and grepping them at scale, recovering GitHub access tokens with write access to company repositories and deployment SSH keys.

Record

Document
"CI Knew There Would Be Bugs Here" — Exploring Continuous Integration Services as a Bug Bounty Hunter
Researcher
EdOverflow, Justin Gardner and Corben Leo
Published by
EdOverflow
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of EdOverflow, Justin Gardner and Corben Leo, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .