Lune

CCS2026顶会

Keys on Doormats: Exposed API Credentials on the Web

Nurullah Demir, Yash Vekaria, Georgios Smaragdakis, Zakir Durumeric

2026年份
2被引次数

摘要

API (Application Programming Interface) keys allow applications to authenticate themselves to third-party services. Inadvertent public exposure of these credentials can pose significant consequences, as adversaries can use them to gain privileged access to other services. In this paper, we measure API credential exposure on the web by analyzing 10M rendered websites. Our findings reveal that API credential exposure on the web is widespread, affecting organizations such as global banks and core infrastructure providers. We identify 1,748 credentials for accessing 14 providers (e.g., cloud and payment services). Crucially, we demonstrate that these exposures are largely missed by static analysis. By characterizing web-specific exposure vectors and root causes, we find that 62% of JavaScript-based exposures manifest exclusively within compiled deployment bundles, while 16% propagate dynamically through third-party resource inclusions. Moreover, our longitudinal analysis shows these credentials often persist for months to years. We conclude by discussing our responsible disclosure efforts and outlining mitigations to secure web deployment pipelines in the future.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext bb059ec3-b9a2-4c28-903d-9ba2f025e960

它引用的顶会 Paper13

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖