skipLink.label

Quest 44 - Secret Scanner

Quest 44: Secret Scanner

easy 15-20 minutes

🎯 Learning Objectives

  • ✅ Identify common secret patterns (API keys, passwords, tokens) in source code
  • ✅ Understand why hardcoded secrets are a critical security vulnerability
  • ✅ Build a scanner that detects secrets using regex pattern matching
  • ✅ Recognize AI-generated code that may accidentally embed test secrets

📖 Concept: Hardcoded Secrets — The Silent Killer

ในทุกๆ วัน มี API keys, passwords, และ tokens ถูก commit ขึ้น GitHub อย่างไม่ตั้งใจ สิ่งเหล่านี้เรียกว่า “hardcoded secrets” — ข้อมูลลับที่ถูกฝังไว้ใน source code แทนที่จะอยู่ใน environment variables หรือ secrets manager

ปัญหาคือ: เมื่อคุณ commit secret ขึ้น public repository แม้จะลบ commit แล้ว ก็ยังอยู่ใน git history — และ bots ที่เฝ้าดู GitHub อยู่ตลอด 24/7 จะ discover ได้ภายในไม่กี่นาที

// ❌ ห้ามทำ — hardcoded API key
const apiKey = 'sk-abc123def456ghi789';
// ❌ ห้ามทำ — hardcoded database password
const dbPassword = 'super_secret_password_123';
// ✅ ถูกต้อง — ใช้ environment variable
const apiKey = process.env.API_KEY;
const dbPassword = process.env.DB_PASSWORD;

Think of secrets like house keys: you wouldn’t tape your house key to the front door. Don’t tape your API keys to your source code.


⚙️ How It Works

Common Secret Patterns

Secrets มักจะมีรูปแบบเฉพาะที่สามารถ detect ได้ด้วย regex:

Secret TypePattern ExampleRegex Hint
AWS Access KeyAKIAIOSFODNN7EXAMPLEStarts with AKIA
API Keysk-abc123..., api_key=...Prefixes like sk-, api_key=
Password in codepassword = "...", passwd: "..."Keywords + assignment
Private Key-----BEGIN RSA PRIVATE KEY-----PEM format headers
JWT TokeneyJhbGci...Starts with eyJ (base64)

The Scanner Strategy

1. Read source code line by line
↓
2. Match each line against known secret patterns
↓
3. Filter out false positives (test files, comments, placeholders)
↓
4. Return list of detected secrets with type and location

💡 Example: Secret Scanner in Action

function scanSecrets(code) {
const patterns = [
{ type: 'AWS Key', regex: /AKIA[0-9A-Z]{16}/g },
{ type: 'API Key', regex: /(?:api[_-]?key|apikey)\s*[:=]\s*['"][^'"]{8,}['"]/gi },
{ type: 'Password', regex: /(?:password|passwd|pwd)\s*[:=]\s*['"][^'"]{4,}['"]/gi },
{ type: 'Private Key', regex: /-----BEGIN.*PRIVATE KEY-----/g },
{ type: 'JWT Token', regex: /eyJ[A-Za-z0-9_-]{20,}\.eyJ[A-Za-z0-9_-]{20,}/g },
{ type: 'Generic Secret', regex: /(?:secret|token)\s*[:=]\s*['"][^'"]{8,}['"]/gi },
];
const detections = [];
const lines = code.split('\n');
for (let i = 0; i < lines.length; i++) {
for (const { type, regex } of patterns) {
const matches = lines[i].match(regex);
if (matches) {
detections.push({
line: i + 1,
type,
value: matches[0],
});
}
}
}
return detections;
}

Key insight: A good secret scanner needs multiple patterns because different providers use different key formats. AWS keys look different from GitHub tokens, which look different from generic passwords.


⚠️ Common Mistakes

Mistake 1: Only checking for “password”

“I’ll just search for the word ‘password’” → Secrets come in many forms: API keys, tokens, connection strings, private keys. A comprehensive scanner needs multiple patterns.

Mistake 2: Flagging test data as secrets

“The scanner found ‘test123’ in the test file” → Distinguish between real secrets in production code and placeholder values in test files. Use context (file path, variable naming) to reduce false positives.

Mistake 3: Missing encoded secrets

“The secret is base64 encoded, so it doesn’t look like a password” → Attackers often encode secrets to avoid detection. Check for base64 patterns and common encoding schemes.

Mistake 4: Not scanning comments

“Comments aren’t executable code” → Developers sometimes paste secrets in comments as “temporary” notes. These are just as dangerous as secrets in code.


📝 Knowledge Check

📝 Knowledge Check

Q1:ทำไม hardcoded secrets ใน source code ถึงอันตราย?

Q2:AWS Access Key มีรูปแบบใด?

Q3:การ scan secrets ควรตรวจสอบอะไรบ้าง?


🏋️ Quest: Secret Scanner

เขียน secret scanner ที่ตรวจจับ hardcoded credentials ใน source code — AI มักจะ suggestion โค้ดที่ฝัง secrets ไว้ใน example code โดยไม่รู้ตัว!

  1. Download ไฟล์เริ่มต้นของ quest:

    Terminal window
    npx bluebeltdojo download quest-44-secret-scanner
    cd quest-44-secret-scanner
  2. เปิด problem.js ใน editor ของคุณพร้อมความช่วยเหลือของ AI

  3. Implement scanSecrets(code) ที่ตรวจจับ:

    • API keys (AWS, generic patterns)
    • Hardcoded passwords
    • Private keys (PEM format)
    • JWT tokens
    • Return results พร้อม line number, type, และ matched value
  4. ตรวจสอบ solution ของคุณ:

    Terminal window
    node test.js

การตรวจสอบ

Terminal window
node test.js

When all tests pass, you will see the completion message.


ส่งคำตอบ

When tests pass, submit your solution:

Terminal window
npx bluebeltdojo submit

ต้องตั้งค่า access code ก่อน: npx bluebeltdojo setup <code>

คำใบ้

  • ใช้ regex patterns ที่แตกต่างกันสำหรับแต่ละ type ของ secret
  • นึกถึงรูปแบบที่พบบ่อย: AKIA... (AWS), sk-... (generic API key), -----BEGIN... (private key)
  • อย่าลืม return line number เพื่อให้ developer แก้ไขได้ง่าย
  • ถ้าติดขัด ลองนึกว่า secrets ของ service ต่างๆ มีรูปแบบยังไง