403
-Access Denied
-- You don't have the necessary clearance to access this sector of the app. -
-diff --git a/.github/assets/banner.png b/.github/assets/banner.png deleted file mode 100644 index e5f3647..0000000 Binary files a/.github/assets/banner.png and /dev/null differ diff --git a/.gitignore b/.gitignore index a91db0d..e69de29 100644 --- a/.gitignore +++ b/.gitignore @@ -1,27 +0,0 @@ -# build output -dist/ -# generated types -.astro/ - -# dependencies -node_modules/ - -# logs -npm-debug.log* -yarn-debug.log* -yarn-error.log* -pnpm-debug.log* - - -# environment variables -.env -.env.production - -# macOS-specific files -.DS_Store - -result/ - -# code editors -.idea/ -.vscode/ diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 7e821b3..5c06d8d 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -6,7 +6,7 @@ First off, thank you for considering contributing to **Default Creds**! By organ 1. **Fork** the repository. 2. Create a **new branch** for your addition (`git checkout -b add-[manufacturer-name]`). -3. Add or update the YAML file in the `src/data/` directory. +3. Add or update the YAML file in the `data/` directory. 4. **Validate** your YAML structure (see the schema below). 5. Commit your changes and **open a Pull Request**. @@ -21,7 +21,7 @@ To keep the database consistent, we use a **Manufacturer-First** approach. Each ### Template -If the manufacturer file doesn't exist, create it in `src/data/`. If it exists, simply add your product to the `entries` list. +If the manufacturer file doesn't exist, create it in `data/`. If it exists, simply add your product to the `entries` list. ```yaml name: "Manufacturer Name" # Full name of the brand diff --git a/README.md b/README.md index a65bef0..b06982f 100644 --- a/README.md +++ b/README.md @@ -1,86 +1,36 @@
- A centralized repository of factory-set credentials. Designed for pentesters and security researchers to identify default access points during engagements - or infrastructure audits. -
-- This open-source app parses structured YAML files. It performs real-time - searches across service names and versions via a lightweight astro engine. -
-- Security is a collective effort. Contribute by adding new YAML - definitions for missing devices or updating existing ones directly via - Pull Requests on GitHub. -
-{randomEmoji}
- {#if cleanedText} -- Can't find any creds for '{cleanedText}'. -
- {:else} -No credentials found for this search.
- {/if} -- You can contribute to the project by submitting new credentials on our - repo. -
-- {result.comment} -
-- You don't have the necessary clearance to access this sector of the app. -
-- The page you are looking for doesn't exist or has been moved. -
-- The server encountered an unexpected error. -
-- Integrate our community-driven default credentials database into your - own security tools. -
-Base Endpoint
- /api/search?q={query}
- | Parameter | -Type | -Default | -Description | -
|---|---|---|---|
| q | -string | -- | -Target name or tag (e.g. "admin", "ubnt") |
-
| page | -number | -1 | -Page number for pagination results. | -
| size | -number | -10 | -Results per page (Min: 1, Max: 50) | -
- // 1. Basic search for cisco admin panels -
-curl -X GET "https://default-creds.hadi.icu/api/search?q=cisco"
- HTTP/1.1 200 OK
- - // 2. Specific pagination request -
-curl -G "https://default-creds.hadi.icu/api/search" \
- -d "q=cisco" \
- -d "page=2" \
- -d "size=5"
- {
- "results": [
- {
- "manufacturer": "Ubiquiti",
- "name": "UniFi",
- "icon": "ubnt-icon",
- "tags": ["network", "router"],
- "version": "all",
- "user": "ubnt",
- "pass": "ubnt"
- }
- ...
- ],
- "pagination": {
- "totalResults": 42,
- "totalPages": 5,
- "currentPage": 1,
- "pageSize": 10
- }
- }
- - This API is provided for educational and authorized penetration - testing only. Excessive requests may lead to temporary IP - blacklisting. You can found the full database on Github. Contribute - to the database on GitHub. -
-- Find default credentials for many devices and software. Contribute to the database by submitting new credentials or updating existing ones. -
-Last updated: March 2026
- -- Default Creds is a free, open-source tool for security researchers and pentesters. This page explains - what data is collected when you use this site and why. -
- -- This site uses Umami, - a privacy-focused analytics tool. Umami collects the following anonymized data: -
-- Umami does not store IP addresses. Instead, it generates a daily rotating hash from your IP, - browser, and a server-side secret. This hash is used solely to distinguish unique visits within - a single day and cannot be reversed or linked back to you. -
- -
- All analytics data is stored on our own self-hosted server. No data is sent to third-party
- analytics providers. The Umami instance is hosted at umami.hadi.icu.
-
- Since no personal data is collected, there is nothing to access, correct, or delete. If you - still have concerns, you can reach out via the contact in our - security.txt. -
- -
- Umami respects the DNT (Do Not Track) header. If your browser has DNT enabled,
- no client-side analytics will be collected for your session.
-
- However, when a search is performed, the query and whether it returned results are logged - server-side, with no user information attached (no IP, no browser, no session identifier). - This is used solely to identify missing manufacturers or products in the database and improve - the dataset. -
- -- If anything changes, this page will be updated with a new date at the top. -
-