Sniffing out credentials
TruffleHog: Sniffing Out Credentials with Ease
TruffleHog is a specialized Chrome extension aimed at enhancing digital safety and precision in pentests and code reviews. It significantly aids in identifying potential security loopholes by actively sniffing out API keys and credentials on the accessed websites. It’s an invaluable tool to ensure swift detection of potent risks that may go unnoticed or require strenuous manual effort to discover.
Extension stats
Risk impact: High risk impact
Risk likelihood:
Manifest version: 2
Permissions:
Size: 35.44K
Email: fo*****@trufflesec.com
Other platforms
Not available on Android
Not available on Firefox
Not available on Edge
Want to check extension ranking and stats more quickly for other Chrome extensions?
Install
Chrome-Stats extension
to view Chrome-Stats data as you browse the Chrome Web Store.
Extension summary
The TruffleHog chrome extension looks for API keys and credentials on websites visited, and alerts you if there are any present. This is useful for doing pentests and code reviews, because it helps identify keys that would otherwise either be missed or have to be searched for manually
User reviews
The popups are broken. Sometimes there are like ten of them with the same content. They block the browser until you interact with the pop-up. Notifications would work way better.
thanks for publishing this extension
api keys exposed
Extension safety
Risk impact
Trufflehog requires some sensitive permissions that could impact your browser and data security. Exercise caution before installing.
Risk likelihood
Trufflehog has earned a fairly good reputation and likely can be trusted.
Upgrade to see risk analysis details
Similar extensions
Here are some Chrome extensions that are similar to Trufflehog:
DotGit Shodan YesWeHack VDP Finder Tracy Vulners Web Scanner XSS OWASP Penetration Testing Kit Google Maps Api Checker FindSomething Hack-Tools CounterXSS retire.js
davtur19
4.83
10,000+
https://shodan.io
4.54
100,000+
acc+browserext
5.00
1,000+
jacob.heath.ncc
4.00
595
vankyver
4.55
9,000+
totofish2021
5.00
2,000+
https://pentestkit.co.uk
4.81
20,000+
https://sites.google.com/view/maps-api-key
N/A
815
ResidualLaugh
4.85
20,000+
Ludovic COULON & Riadh BOUCHAHOUA
4.63
30,000+
playarun93
5.00
499
jadwigaostrowska803
4.89
20,000+