forked from mirrors/kingfisher
27 lines
749 B
YAML
27 lines
749 B
YAML
rules:
|
|
- name: Uber Server Token
|
|
id: kingfisher.uber.1
|
|
pattern: |
|
|
(?xi)
|
|
\b
|
|
uber
|
|
(?:.|[\n\r]){0,32}?
|
|
\bserver[_-]?token\b
|
|
(?:.|[\n\r]){0,16}?
|
|
[=:"'\s]
|
|
['"]*
|
|
(
|
|
[A-Za-z0-9_-]{36,44}
|
|
)
|
|
['"\s]
|
|
pattern_requirements:
|
|
min_digits: 2
|
|
min_entropy: 3.5
|
|
confidence: high
|
|
examples:
|
|
- "config.uber.server_token = \"Cyob8XIWekjc6pbbRIJbw-Y2Y38QXzIVBbXpPtW\""
|
|
- "uber, server_token: 'PCLca4a2cQl2OR88-tZ_5X_yYmkzHF4zqoK838X_'"
|
|
references:
|
|
- https://developer.uber.com/docs/riders/guides/authentication/server-token
|
|
# No active public validation endpoint: Uber's server token API
|
|
# is deprecated and no longer publicly accessible.
|