envfucker
27 subscribers
2 photos
1 video
4 links
Download Telegram
Channel created
Forwarded from @half lounge
Media is too big
VIEW IN TELEGRAM
πŸš€ ENV-FUCKER: Fast exposure recon for "authorized" infrastructure.

What it is
One binary: TUI wizard, CLI batch, streaming crawler, or timed auto loop. Same scanner, same artifacts everywhere.

Core scanning
- ~1.7k effective paths per host with encoding tricks.
- Three transports: HTTP, HTTPS, DNS-smart HTTPS for correct virtual hosts.
- Strong validator: size/content-type gates, binary/HTML-noise handling, dedupe, caps, resumable checkpoints, optional diff vs. previous run.
- Worker presets: 256 up to ~2k goroutines.

Discovery
- Sources: File/stdin lists, CT roots, CIDR expansion, or crawler mode (multi-source BFS + TLS-name feedback).
- Shodan: Free InternetDB mixed in; paid membership seeding requires a key/credit budget.

CVE layer
- 75 built-in fingerprints, 122 mapped CVE IDs.
- KEV + live FIRST EPSS, version-aware applicability, junk-aware saves.

Outputs & Ops
- Logs: Stable run/finding IDs, critical mirror, secrets table, AI aggregate, per-vendor key extracts.
- Extras: Live verification, webhooks, HTML/CSV reports, Nuclei-style URL feed, Prometheus metrics, cross-host dedupe, run bundle with manifest.
- Networking: Rotating proxy pool, preflight checks, error visibility, output profiles, legacy mode.

@half to reserve a spot.
Another update just landed πŸš€

Expansions πŸ“¦:

β€’ New pattern: anthropic-admin-key (`sk-ant-admin…`)
β€’ Base64 body expansion β€” keys hidden in K8s/CI blobs now surface automatically πŸ”
β€’ Anchor-gated decoder: max 8 windows Γ— 4 KiB, 256 KiB budget
β€’ Cross-view dedupe so the same secret never double-scores πŸ›‘οΈ
β€’ Added stringData: sk-proj-, sk-or-, hf_, "api_key": expansion anchors πŸ”‘
β€’ 17 new corpus paths (Bun, Deno, Wrangler .dev.vars, ArgoCD, Netlify, ORM configs)

CVE Expansion + New Discovery πŸ”Ž

β€’ 4 new CVE catalog YAML files (~33 fingerprints):
apache.yaml β€” httpd, Tomcat, Struts, Solr, Druid, Superset, NiFi, OFBiz
nginx.yaml β€” nginx, NGINX Unit, OpenResty, ingress-controller, NPM
web-apps.yaml β€” Laravel, Django, Rails, WordPress, Joomla, Moodle, Drupal, Magento, PrestaShop, TYPO3, OpenCart
middleware.yaml β€” JBoss, WebLogic, ColdFusion, Exchange OWA (ProxyLogon), SharePoint
*Covers 20+ KEV entries (CISA Known Exploited)* 🚨
β€’ 8 new signal patterns: github_pat_ (fine-grained PATs), glpat- (GitLab PAT), glcbt- (GitLab CI token), CLOUDFLARE_API_TOKEN, FlyV1 ([Fly.io](http://Fly.io/)), pscale_tkn_ (PlanetScale), [dp.st](http://dp.st/) (Doppler service), HUBSPOT_API_KEY
β€’ signalCategory coverage test β€” fails loudly when a new pattern skips the 4-file checklist ⚠️
β€’ 3 opt-in discovery sources (activate via env var, zero cost otherwise):
GITHUB_TOKEN β†’ GitHub Code Search
VT_API_KEY β†’ VirusTotal passive DNS
NETLAS_API_KEY β†’ [Netlas.io](http://Netlas.io/)
β€’ 33 pre-existing signalCategory gaps fixed (`openai-session`, xai-key, firebase, azure-openai, npm-auth-token, square, plaid, etc.)

NEW FUNCTIONS βš™οΈ
β€’ HTML report now fully interactive (vanilla JS, no CDN):
β€” Live search/filter across all hits πŸ”
β€” Clickable sort on Bucket and Score columns πŸ“Š
β€” CSV export button (visible rows only) πŸ“₯
β€’ Smart (auto) TUI preset β€” reads input file line count, picks:
≀100 hosts β†’ Targeted | ≀10K β†’ Fast & Loose
≀500K β†’ Mass Scan | >500K β†’ Beast 🦍
😎
Please open Telegram to view this post
VIEW IN TELEGRAM
NEW UPDATE RELEASED

- Added 6 missing signalCategory entries: wp-db-password β†’ databases, wp-keys, laravel-app-key, django-secret, nextjs-secret β†’ api-keys

- Added jwt-alg-none β†’ tokens

- Upgraded stability
Nearly 500 hits in just 3 hours of run 😊
Please open Telegram to view this post
VIEW IN TELEGRAM
envfucker pinned a video
New Update:

- 67 more Shodan presets (was 27) πŸ”
- 24 new CVE fingerprints πŸ›‘οΈ
- Cross run dedupe (re-running same output directory skips already scanned hosts) ⚑
- Stability Fixes πŸ› οΈ
πŸ›  Working on the biggest and hopefully last update of the program (still updating weekly with new CVE's)! After this update, I'll release 1 KEY PER WEEK. ⚠️ The price will increase every time a key is sold! πŸš€
Little recap on the tool: πŸ”

Probes
authorized targets across 3 transport modes (HTTP, HTTPS, HTTPS+DNS) against a corpus of 943 paths β€” .env files, cloud credentials, Terraform state, Spring Boot actuators, CI configs and more. Up to 1,000 goroutines running simultaneously, ~**2,800 probes** per host. ⚑

Discovers
targets from 13 sources β€” crt.sh, CertSpotter, urlscan, OTX, CommonCrawl, Shodan, RapidDNS, bufferover, subdomain.center, brute-DNS, GitHub codesearch, VirusTotal, Netlas. Optional ASN expansion, permutation, archive.org. 🌐

Detects & live-verifies
secrets from 80 providers: AWS, GitHub, OpenAI, Anthropic, Stripe, Slack, 24+ AI/LLM APIs (Groq, Mistral, Replicate, Together, Perplexity…), BaaS platforms, deployment services and more β€” hitting vendor endpoints directly to confirm if keys are still active. πŸ”

CVE correlation
on 129 fingerprinted products (Confluence, GitLab, Jenkins, Spring, Kubernetes…) covering 230 CVEs enriched with CISA KEV flags and EPSS exploit probability scores. πŸ›‘οΈ

Output:
streaming JSONL, CSV, self-contained HTML report, per-provider key files, Nuclei feed, Discord/Slack webhook β€” everything written atomically with crash-resume support. πŸ“€
Accepting first preorder for 1500$/month , if you don’t know what the program is useful for just don’t write me I won’t sell it @half
1st key sold, next drop next friday
πŸ‘Ž4
Im currently merging envfucker with my automatic audit tool. No market equivalent exists. Interested? Weekly price: xx.xxx. DM me. Access includes my personal RAG (X4 A40 Nvidia + 150GB RAM server) with constant ingestion and manual auditing.
In the meanwhile im leaving 5 spots for envfucker 2k$/month , needs at least 12GB of VRAM + at least 32GB of RAM

also needs shodan api key ( enterprise one if you want to use it at its fully capacity , costs around ~150$ ) + proxies ( datacenter runs good )

@half for more infos and to purchase