Sploitus

Exploit for tartufo

kitploit · 2026-09-08

Exploit Code

MARKDOWN117 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-GODADDY-TARTUFO
# ![tartufo logo](https://assets.kitploit.com/production/public/readmes/6531/33ec384deaf1a88e03ba50f2b7b8b60caa5b151bebfbc4265e05e8966259425d.png)

![ci](https://github.com/godaddy/tartufo/workflows/ci/badge.svg) ![Codecov](https://img.shields.io/codecov/c/github/godaddy/tartufo) ![PyPI](https://img.shields.io/pypi/v/tartufo) ![PyPI - Status](https://img.shields.io/pypi/status/tartufo) ![PyPI - Python Version](https://img.shields.io/pypi/pyversions/tartufo) ![PyPI - Downloads](https://img.shields.io/pypi/dm/tartufo) ![Documentation Status](https://readthedocs.org/projects/tartufo/badge/?version=latest) ![License](https://img.shields.io/github/license/godaddy/tartufo)

`tartufo` 在 git 仓库中搜索秘密,深入挖掘提交历史和分支。这对于发现意外提交的秘密非常有效。`tartufo` 也可以用作 git 预提交钩子,在更改提交到仓库之前检查其中的秘密。

该工具将遍历每个分支的整个提交历史,检查每个提交的每个 diff,并检测秘密。检测方式包括正则表达式和熵值检查。对于熵值检查,tartufo 会评估每个 diff 中大于 20 个字符、由 base64 字符集或十六进制字符集组成的文本块的香农熵。如果发现任何高熵字符串(>20 个字符),则会将其打印到屏幕上。

## 示例

![示例问题](https://assets.kitploit.com/production/public/readmes/6531/03974e5fd21cb205d9dd249cb5d09d382d005311bc98bb553822115602090a3b.png)

## 文档

我们的主要文档站点由 Read The Docs 托管,地址为: https://tartufo.readthedocs.io

## 用法

root@kitploit:~
    
    
    Usage: tartufo [OPTIONS] COMMAND [ARGS]...
    
      Find secrets hidden in the depths of git.
    
      Tartufo will, by default, scan the entire history of a git repository for
      any text which looks like a secret, password, credential, etc. It can also
      be made to work in pre-commit mode, for scanning blobs of text as a pre-
      commit hook.
    
    Options:
      --default-regexes / --no-default-regexes
                                      Whether to include the default regex list
                                      when configuring search patterns. Only
                                      applicable if --rules is also specified.
                                      [default: default-regexes]
      --entropy / --no-entropy        Enable entropy checks.  [default: entropy]
      --regex / --no-regex            Enable high signal regexes checks.
                                      [default: regex]
      --scan-filenames / --no-scan-filenames
                                      Check the names of files being scanned as
                                      well as their contents.  [default: scan-
                                      filenames]
      -of, --output-format [json|compact|text|report]
                                      Specify the format in which the output needs
                                      to be generated `--output-format
                                      json/compact/text/report`. Either `json`,
                                      `compact`, `text` or `report` can be
                                      specified. If not provided (default) the
                                      output will be generated in `text` format.
      -od, --output-dir DIRECTORY     If specified, all issues will be written out
                                      as individual JSON files to a uniquely named
                                      directory under this one. This will help
                                      with keeping the results of individual runs
                                      of tartufo separated.
      -td, --temp-dir DIRECTORY       If specified, temporary files will be
                                      written to the specified path
      --buffer-size INTEGER           Maximum number of issue to buffer in memory
                                      before shifting to temporary file buffering
                                      [default: 10000]
      --git-rules-repo TEXT           A file path, or git URL, pointing to a git
                                      repository containing regex rules to be used
                                      for scanning. By default, all .json files
                                      will be loaded from the root of that
                                      repository. --git-rules-files can be used to
                                      override this behavior and load specific
                                      files.
      --git-rules-files TEXT          Used in conjunction with --git-rules-repo,
                                      specify glob-style patterns for files from
                                      which to load the regex rules. Can be
                                      specified multiple times.
      --config FILE                   Read configuration from specified file.
                                      [default: tartufo.toml]
      --target-config/--no-target-config
                                      Enable or Disable processing of the config file in the
                                      repository or folder being scanned
                                      i.e. config files like tartufo.toml or pyproject.toml
                                      [default: target-config]
      -q, --quiet / --no-quiet        Quiet mode. No outputs are reported if the
                                      scan is successful and doesn't find any
                                      issues
      -v, --verbose                   Display more verbose output. Specifying this
                                      option multiple times will incrementally
                                      increase the amount of output.
      --log-timestamps / --no-log-timestamps
                                      Enable or disable timestamps in logging
                                      messages.  [default: log-timestamps]
      --entropy-sensitivity INTEGER RANGE
                                      Modify entropy detection sensitivity. This
                                      is expressed as on a scale of 0 to 100,
                                      where 0 means "totally nonrandom" and 100
                                      means "totally random". Decreasing the
                                      scanner's sensitivity increases the
                                      likelihood that a given string will be
                                      identified as suspicious.  [default: 75;
                                      0<=x<=100]
      --color / --no-color            Enable or disable terminal color. If not
                                      provided (default), enabled if output is a
                                      terminal (TTY).
      -V, --version                   Show the version and exit.
      -h, --help                      Show this message and exit.
    
    Commands:
      pre-commit        Scan staged changes in a pre-commit hook.
      scan-remote-repo  Automatically clone and scan a remote git repository.
      scan-folder       Scan a folder.
      scan-local-repo   Scan a repository already cloned to your local system.
    

## 贡献

欢迎所有贡献者和贡献!请参阅我们的 贡献文档 以获取更多信息。

## 致谢

本项目的灵感源自 Dylan Ayrey 在 truffleHog 项目上所做的工作,并在此基础上进行了构建。