|
|
|
|
|
by trebligdivad
1003 days ago
|
|
How would a pentest find that? Ok in this case it's splattered onto github; but the main point here is that you might have some unknown number of SAS tokens issued to unknown storage that you probably haven't any easy way to revoke. |
|
- finding the token directly in the repo
- reviewing all tokens issued