4 ms·
Folks, please remember to PURGE GIT COMMIT HISTORY of the file. It does no good to simply remove a password if it's there in plain (historical) sight. https:/
by weej 8y ago
Folks, please remember to PURGE GIT COMMIT HISTORY of the file. It does no good to simply remove a password if it's there in plain (historical) sight.
https://help.github.com/articles/removing-sensitive-data-from-a-repository/ https://help.github.com/articles/removing-sensitive-data-fro...
- stevekemp 8y agoAnd obviously rotate the exposed credentials - because even if it was only public for "a while" it could have been viewed by many users.
- meowface 8y agoPlus it could've been archived by another website or a private scraping tool which looks for exactly these sorts of exposures. Removing it from the git history is almost irrelevant and just stops future people who find it from sniffing around. The crucial part is rotating the credentials and ensuring the credentials aren't used anywhere else. The second step should be reviewing all logs to ensure no unauthorized logins occurred before the credentials were changed (even if the exposure was only exploitable for a few seconds).