5 ms·
To maintain dev ops best practices such as prohibiting nginx from sending dotfiles (.env, .git, etc) takes time. It’s understandable that you made a mistake. Bu
by ryanmccullagh 7y ago
To maintain dev ops best practices such as prohibiting nginx from sending dotfiles (.env, .git, etc) takes time. It’s understandable that you made a mistake. But how did they get access to the actual dB? Did you expose it over the public internet?
- ngranja19 7y agoExactly. You could access to it like viralquotesonline.com/.env. I did several mistakes for sure. It was my first project launched to the world and the first time I used Laravel, is a bit embarrassing to be honest, but hopefully helps other to realize that they are in a risk too.
- ryanmccullagh 7y agoWell it’s a good lesson and definitely don’t pay them. but I’m still not sure how they accessed the DB. Did you expose port 3306 over a public IP? Small things like this are one of the reasons I founded the PHP hosting platform, Amezmo where secure production ready container instances can be launched in seconds.
- ThePowerOfFuet 7y ago>And if you call in the next twenty minutes...
- jlis 7y agoWhat I don't get is how the .env file was even served when Laravel uses the public/index.php as starting point, so your root Folder should have been the public/ folder, not the application folder. Mistakes like this happen, but it takes courage to post about it. Thanks for sharing it.
- ngranja19 7y agoI'm not totally sure I'm not a Laravel expert I just use it as a backend api so I believe I exposing the entire Laravel folder instead just the public. And yes is embarrassing haha.
- saluki 7y agoI was curious too how this could happen, since the .env wouldn't normally be in the public folder. Laravel is a great framework, check out Laracasts.com and forge.laravel.com, it's a deployment tool that will spin up a VPS on AWS, Digital Ocean, etc. with the proper configuration.
- tluyben2 7y agoBut how did that work in the first place? Not that it is good practice etc however, normally your webserver for Laravel would be pointing to $MYSITE_DIR/public and .env would be $MYSITE_DIR/.env. So how did you end up getting it exposed there?