Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
63 changes: 63 additions & 0 deletions pkg/detectors/rancher/rancher.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
package rancher

import (
"context"

regexp "github.com/wasilibs/go-re2"

"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
"github.com/trufflesecurity/trufflehog/v3/pkg/pb/detector_typepb"
)

type Scanner struct{}

var _ detectors.Detector = (*Scanner)(nil)

var (
// Match known Rancher/Cattle variable names followed by the token value.
// (?i:...) scopes case-insensitivity to the variable name only; the capture
// group stays case-sensitive because Rancher tokens are lowercase alphanumeric.
// The optional quote after the name covers quoted JSON keys
// (e.g. `"CATTLE_TOKEN": "<token>"`).
keyPat = regexp.MustCompile(
`(?i:CATTLE_TOKEN|RANCHER_TOKEN|CATTLE_BOOTSTRAP_PASSWORD|RANCHER_API_TOKEN|RANCHER_SECRET_KEY)` +
`["']?\s*[=:]\s*["']?([a-z0-9]{54,64}\b)["']?`)
)

func (s Scanner) Keywords() []string {
return []string{"cattle_token", "cattle_bootstrap_password", "rancher_token", "rancher_api_token", "rancher_secret_key"}
}

// FromData finds and optionally verifies Rancher API tokens in a chunk of data.
// Verification is not supported without a live CATTLE_SERVER URL; matched tokens
// are returned as unverified (Verified=false, no VerificationError).
func (s Scanner) FromData(_ context.Context, _ bool, data []byte) ([]detectors.Result, error) {
dataStr := string(data)
seen := make(map[string]struct{})

var results []detectors.Result
for _, m := range keyPat.FindAllStringSubmatch(dataStr, -1) {
token := m[1]
if _, ok := seen[token]; ok {
continue
}
seen[token] = struct{}{}

results = append(results, detectors.Result{
DetectorType: detector_typepb.DetectorType_Rancher,
Raw: []byte(token),
SecretParts: map[string]string{"token": token},
})
}

return results, nil
}

func (s Scanner) Type() detector_typepb.DetectorType {
return detector_typepb.DetectorType_Rancher
}

func (s Scanner) Description() string {
return "Rancher is a Kubernetes management platform used by 37,000+ organizations. " +
"Rancher API tokens provide full cluster admin access and must be treated as critical secrets."
}
110 changes: 110 additions & 0 deletions pkg/detectors/rancher/rancher_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,110 @@
package rancher

import (
"context"
"strings"
"testing"

"github.com/google/go-cmp/cmp"

"github.com/trufflesecurity/trufflehog/v3/pkg/detectors"
"github.com/trufflesecurity/trufflehog/v3/pkg/engine/ahocorasick"
)

var (
validToken = "jswpl27hs8pd88rmw2mgfgrjtpljp85fd5v7rhdwr2s6z22hvt6vjt"
invalidToken = "notavalidtoken"
)

func TestRancher_Pattern(t *testing.T) {
d := Scanner{}
ahoCorasickCore := ahocorasick.NewAhoCorasickCore([]detectors.Detector{d})

tests := []struct {
name string
input string
want []string
}{
{
name: "env file - CATTLE_TOKEN",
input: `
CATTLE_SERVER=https://rancher.example.com
CATTLE_TOKEN=` + validToken,
want: []string{validToken},
},
{
name: "env file - RANCHER_API_TOKEN",
input: `
RANCHER_API_TOKEN=` + validToken,
want: []string{validToken},
},
{
name: "quoted value",
input: `CATTLE_BOOTSTRAP_PASSWORD="` + validToken + `"`,
want: []string{validToken},
},
{
name: "json object - quoted key",
input: `{"CATTLE_TOKEN": "` + validToken + `"}`,
want: []string{validToken},
},
{
name: "json object - quoted key, no space",
input: `{"RANCHER_TOKEN":"` + validToken + `"}`,
want: []string{validToken},
},
{
name: "uppercase token - should not detect",
input: `CATTLE_TOKEN=` + strings.ToUpper(validToken),
want: []string{},
},
{
name: "no context - should not detect",
input: `random_string=` + validToken,
want: []string{},
},
{
name: "invalid token length",
input: `CATTLE_TOKEN=` + invalidToken,
want: []string{},
},
{
name: "token too long - should not detect prefix",
input: `CATTLE_TOKEN=` + validToken + "zzzzzzzzzzzz",
want: []string{},
},
}

for _, test := range tests {
t.Run(test.name, func(t *testing.T) {
matchedDetectors := ahoCorasickCore.FindDetectorMatches([]byte(test.input))
if len(test.want) > 0 && len(matchedDetectors) == 0 {
t.Errorf("keywords '%v' not matched by: %s", d.Keywords(), test.input)
return
}

results, err := d.FromData(context.Background(), false, []byte(test.input))
if err != nil {
t.Errorf("error = %v", err)
return
}

actual := make(map[string]struct{}, len(results))
for _, r := range results {
if len(r.RawV2) > 0 {
actual[string(r.RawV2)] = struct{}{}
} else {
actual[string(r.Raw)] = struct{}{}
}
}
expected := make(map[string]struct{}, len(test.want))
for _, v := range test.want {
expected[v] = struct{}{}
}

if diff := cmp.Diff(expected, actual); diff != "" {
t.Errorf("%s diff: (-want +got)\n%s", test.name, diff)
}
})
}
}
2 changes: 2 additions & 0 deletions pkg/engine/defaults/defaults.go
Original file line number Diff line number Diff line change
Expand Up @@ -629,6 +629,7 @@ import (
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/rabbitmq"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/railwayapp"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/ramp"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/rancher"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/rapidapi"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/rawg"
"github.com/trufflesecurity/trufflehog/v3/pkg/detectors/razorpay"
Expand Down Expand Up @@ -1551,6 +1552,7 @@ func buildDetectorList() []detectors.Detector {
&rabbitmq.Scanner{},
&railwayapp.Scanner{},
&ramp.Scanner{},
&rancher.Scanner{},
&rapidapi.Scanner{},
// &raven.Scanner{},
&rawg.Scanner{},
Expand Down
7 changes: 5 additions & 2 deletions pkg/pb/detector_typepb/detector_type.pb.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

1 change: 1 addition & 0 deletions proto/detector_type.proto
Original file line number Diff line number Diff line change
Expand Up @@ -1073,4 +1073,5 @@ enum DetectorType {
SolarWindsObservability = 1069;
HumioAPIToken = 1070;
Resend = 1071;
Rancher = 1072;
}