---
title: "Exposed Secrets - Paste Sites"
canonical: "https://kb.cynergy.app/space/MD/899416402/Exposed%20Secrets%20-%20Paste%20Sites"
format: markdown
---
**Description**

Attackers are constantly monitoring and scanning public paste sites such as Pastebin and many [others ](https://github.com/lorien/awesome-pastebin)Which means that attackers can (and they do) monitor the Paste sites for credentials and sensitive information within the pastes. For this reason, it is best to assume that if you have leaked a secret, it is forever compromised.

**Hacker's View**

As a hacker, I will use tools like [BLUELAY ](https://github.com/xakepnz/BLUELAY)and [Pastebin search](https://pastebinsearch.github.io/) to identify publicly exposed secrets and API keys in paste sites. once identified I will use them to get into the accounts and possibly use them to breach the organization or alternatively use the API keys for self-consumption or resell them on the Darknet. 

**Mitigation**

The mitigation for a leaked credentials incident is divided into two parts:

- Immediate action -
  - Delete the Pate Site entry of the API key or sensitive information
  - Rotate the key or generate a new key - assume that once leaked, someone has already found and possibly used the API key

**Cynergy’s View**

Cynergy constantly collects and indexes leaked sensitive data from Pastebin and other paste sites, Cynergy has a unique algorithm that tries to identify and validate the sensitive data, to reduce the false positive alerts. 

Once identified, Cynergy will help you to remediate the issue automatically. 

Scan for data leaks now.

![image](media://3140788c-2479-405b-981d-d7e597c7e2b0)


**References:**

List of paste sites - [https://github.com/lorien/awesome-pastebin](https://github.com/lorien/awesome-pastebin) 

Paste sites search - [https://pastebinsearch.github.io/](https://pastebinsearch.github.io/) 

BLUELAY Tool - [https://github.com/xakepnz/BLUELAY](https://github.com/xakepnz/BLUELAY)