WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

Conversation

@LloydCoder
Copy link

Adds high-signal templates for detecting leaked credentials from major Nigerian payment and betting platforms in http/secrets/:

  • Paystack live/test secret keys (tinlance-paystack-secret-exposure.yaml)
  • Flutterwave (Rave) secret keys (tinlance-flutterwave-secret-exposure.yaml)
  • Remita merchant IDs + API keys (tinlance-remita-credentials-exposure.yaml)
  • Interswitch Webpay MAC keys (tinlance-interswitch-webpay-exposure.yaml)
  • SportyBet/BetKing admin tokens (tinlance-sportybet-api-exposure.yaml)

All written/tested by @LloydCoder (Tinlance). Follows TEMPLATE-CREATION-GUIDE.md. No FPs expected due to multi-matchers. Verified with nuclei -validate.

Thanks to ProjectDiscovery! 🇳🇬 #newtemplate

New detector for Paystack key leaks. Follows guidelines. #newtemplate
New detector for flutterwave. Tested with Nuclei v3.x. #newtemplate
New detector for Remita. Tested with Nuclei v3.x. #newtemplate
New detector for interswitch webpay. Tested with Nuclei v3.x. #newtemplate
New detector for sportybet api. Tested with Nuclei v3.x. #newtemplate
LloydCoder added a commit to LloydCoder/semgrep-rules that referenced this pull request Dec 6, 2025
New high-impact rules detecting hardcoded credentials from major Nigerian payment and betting platforms:
• Paystack (live/test keys)
• Flutterwave/Rave
• Remita merchant + hash
• Interswitch MAC keys
• SportyBet/BetKing JWT tokens

Same patterns already shipped in:
- Nuclei: projectdiscovery/nuclei-templates#14253
- TruffleHog: trufflesecurity/trufflehog#4588

Author: @LloydCoder (Tinlance) 🇳🇬
LloydCoder added a commit to LloydCoder/gitleaks that referenced this pull request Dec 6, 2025
…Coder

Appends high-signal rules to default config for detecting leaked credentials from major Nigerian platforms:
• Paystack secret keys
• Flutterwave/Rave keys
• Remita merchant + hash
• Interswitch MAC keys
• SportyBet/BetKing tokens

Same patterns shipped in:
- Nuclei: projectdiscovery/nuclei-templates#14253
- TruffleHog: trufflesecurity/trufflehog#4588
- Semgrep: semgrep/semgrep-rules#3719

Author: @LloydCoder (Tinlance) 🇳🇬
Tested with `gitleaks detect --config .` — clean, no FPs on sample repos.
New detector for Remita. Tested with Nuclei v3.x. #newtemplate
New detector for interswitch webpay. Tested with Nuclei v3.x. #newtemplate
LloydCoder added a commit to LloydCoder/nigerian-secret-detectors that referenced this pull request Dec 6, 2025
New high-impact rules detecting hardcoded credentials from major Nigerian payment and betting platforms:
• Paystack (live/test keys)
• Flutterwave/Rave
• Remita merchant + hash
• Interswitch MAC keys
• SportyBet/BetKing JWT tokens

Same patterns already shipped in:
- Nuclei: projectdiscovery/nuclei-templates#14253
- TruffleHog: trufflesecurity/trufflehog#4588

Author: @LloydCoder (Tinlance) 🇳🇬
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants