4 ms·
"Passwords" in the title is a bit misleading. Most of these are staging files with little or no sensitive information there. However there is the odd bit of int
by getdavidhiggins 11y ago
"Passwords" in the title is a bit misleading. Most of these are staging files with little or no sensitive information there. However there is the odd bit of interesting data there if you look hard enough.
Github search is an untapped resource just like Algolia Search is on Hackernews. Infact I have largely replaced my Google searches with these ones for more refined and curated results.
- sirwolfgang 11y agoIt's not an untapped resource, there are plenty of bots that search for creds then use them. Here one example: http://www.devfactor.net/2014/12/30/2375-amazon-mistake/ http://www.devfactor.net/2014/12/30/2375-amazon-mistake/
- erikb 11y agoWhat do you mean with staging files, what is not sensitive about username and password of the database?
- getdavidhiggins 11y agoWell a Wordpress production site is a rare and precious thing to find on Github. There are some that exist, but then even if I do find it: 1.) Password will be changed 2.) Possible honeypot 3.) Boring site is boring. No need to hack it. Not popular enough Same goes for other databases on there. An enormous amount of cruft to wade through to get anything remotely juicy/interesting. And the same heuristics apply above: is it really so great that I logged into a boring MYSQL database that is probably being monitored and has nothing interesting in there in the first place?
- thekevan 11y agoI think they mean that a majority of these are instances where someone installed WP to play with it and these are the testing files rather than an actual website they are using. When I installed WP recently, I know I just used a dummy password for testing.