Hmmm my idea would be "Hello from github, We detected that you uploaded credentials to NAME_OF_REPO. We strongly advise against this as it allows attackers to easily gain unauthorized access to your software and infrastructure. Have a look at this blog where we discuss alternatives" EDIT: Just to be clear, I'm not suggesting a ban at all, just a friendly email in response to commits that introduce credentials to publ…
Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
21–30 of 60 posts
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#22Can someone explain why the inurl:server is used? Wouldn't this also work without that (and reveal more results where the keyfile has been renamed)
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#23Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#24Quite often you can go to domain.tld/.git/ and find the files if you know their names. Even major sites - The Hill only fixed it in the past few days.
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#25Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#26You should check out how many services have their entire git repo of their service openly accessible (this allows getting the data out of the git objects, as well as the history). Quite often you can go to domain.tld/.git/ and find the files if you know their names. Even major sites - The Hill only fixed it in the past few days.
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#27www.dulceswilly.com/mysql/BHP_sym/root/usr/local/etc/apache22/server.key
If I was on a non-company IP, I'd be tempted to poke around and see what else is visible...
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#28Google lost its mind when I clicked this link. Signed me out, turned on SafeSearch and threw up some privacy notice dialog at the top of the page.
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#29I apologize for saying this, but... so far, this is violating no stereotypes
Re: Google Search: Inurl:server Filetype:key “-----BEGIN RSA PRIVATE KEY-----”
#30One of the more amusing patterns I spotted in the URLs is where an alarming amount of the filesystem appears to be exposed, e.g.: www.dulceswilly.com/mysql/BHP_sym/root/usr/local/etc/apache22/server.key If I was on a non-company IP, I'd be tempted to poke around and see what else is visible...