4 ms·
> The company's developers accidentally uploaded the entire database to Github Wait, from what I've heard, the programmer just uploaded a configuration file th
by rqs 8y ago
> The company's developers accidentally uploaded the entire database to Github
Wait, from what I've heard, the programmer just uploaded a configuration file that contains the password of the database?
And oh boy, he's not the only one, Maybe GitHub can do something about it.
To the topic: This is the exact reason why I don't support any sort of system that log users personal information without user's control.
Because regardless how strong and secure you think your system is, all it takes is one careless action, then everything blows up.
- dis-sys 8y agoplease don't over estimate their skills and qualification. the leaked database username is root and the password is 123456. the screenshot of the github file can be access here: https://www.secrss.com/articles/4851 https://www.secrss.com/articles/4851 and yes, that "programmer" pushed such highly sensitive company information to his personal github repo.
- subcosmos 8y agoThis happens so frequently, and is easy to scan for, sadly. What is missing is a way to programmatically, and secretly, inform people of their mistakes. I've personally found literally hundreds of examples of this and lack the manpower to file that many tickets....
- jjoonathan 8y agoMissing? I thought they already did that. IIRC a couple of my teammates reported getting emails from github about accidentally uploading AWS credentials and the like.
- hinkley 8y agoWhat is missing is a default or recommended git hook to reject pushes that contain passwords for the patterns that are obvious.
- deleted 8y ago[deleted]
- rqs 8y ago> please don't over estimate their skills and qualification No, I said "careless" rather than "incompetent". Lot's of things could go wrong and cause that, I don't comment on the detail until the reason of why the password end up been pushed to GitHub is explained. Also, I suggest Please REMOVE anything that MAY help to locate the stolen information, including content of the advertising post (Can be keyword searched).
- deleted 8y ago[deleted]
- 0x8BADF00D 8y agoWhy do people store secrets directly in their codebase? It makes me physically ill seeing this. Environment variables exist for a reason.
- ashleyn 8y ago123456 That's the kind of combination an idiot would have on his luggage!
- crisnoble 8y ago> he's not the only one. Too true: https://github.com/search?q=spring.datasource.password%3D123456&type=Code https://github.com/search?q=spring.datasource.password%3D123...