From 7e2b6dd426759b84c8d780734859abcce5204983 Mon Sep 17 00:00:00 2001 From: Hadi <112569860+anotherhadi@users.noreply.github.com> Date: Wed, 21 May 2025 10:45:28 +0200 Subject: [PATCH] Cover your tracks! Signed-off-by: Hadi <112569860+anotherhadi@users.noreply.github.com> --- README.md | 39 +++++++++++++++++++++++++-------------- 1 file changed, 25 insertions(+), 14 deletions(-) diff --git a/README.md b/README.md index b01ed87..7a9f2c7 100644 --- a/README.md +++ b/README.md @@ -83,20 +83,16 @@ gh-recon --username TARGET_USER [--token YOUR_TOKEN] ### Flags ```txt - -deep - Enable deep scan (clone repos, regex search, analyse licenses, etc.) - -email string - Search accounts by email address - -json string - Write results to specified JSON file - -only-commits - Display only commits with author info - -silent - Suppress all non-essential output - -token string - GitHub personal access token (e.g. ghp_...) - -username string - GitHub username to analyze + -d, --deep Enable deep scan (clone repos, regex search, analyse licenses, etc.) + -e, --email string Search accounts by email address + --exclude-repo string Exclude repos from deep scan (comma-separated list) + -j, --json string Write results to specified JSON file + --max-size int Limit the size of repositories to scan (in MB) (Only for deep scan) (default 150) + -c, --only-commits Display only commits with author info + -r, --refresh Refresh the cache (deep scan only) + -s, --silent Suppress all non-essential output + -t, --token string GitHub personal access token (e.g. ghp_...) + -u, --username string GitHub username to analyze ``` ## Example @@ -107,6 +103,21 @@ gh-recon --email myemail@gmail.com --token ghp_ABC123... gh-recon --username anotherhadi --json output.json --deep ``` +## Cover your tracks + +Understanding what information about you is publicly visible is the first step to managing your online presence. gh-recon can help you identify your own publicly available data on GitHub. Here’s how you can take steps to protect your privacy and security: + +- **Review your public profile**: Regularly check your GitHub profile and repositories to ensure that you are not unintentionally exposing sensitive information. +- **Manage email exposure**: Use GitHub's settings to control which email addresses are visible on your profile and in commit history. You can also use a no-reply email address for commits. Delete/modify any sensitive information in your commit history. +- **Be Mindful of Repository Content**: Avoid including sensitive information in your repositories, such as API keys, passwords, emails or personal data. Use `.gitignore` to exclude files that contain sensitive information. + +You can also use a tool like [TruffleHog](github.com/trufflesecurity/trufflehog) to scan your repositories specifically for exposed secrets and tokens. + +**Useful links:** + +- [Blocking command line pushes that expose your personal email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address) +- [No-reply email address](https://docs.github.com/en/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/setting-your-commit-email-address) + ## Contributing Feel free to contribute! See [CONTRIBUTING.md](CONTRIBUTING.md) for details.