3 ms·
The title is a bit misleading. It's not wrong. Someone used a leaked API key to do card testing. That explains why someone might be interested in the API key.
by quelltext 4y ago
The title is a bit misleading.
It's not wrong. Someone used a leaked API key to do card testing. That explains why someone might be interested in the API key. However, the bigger part of the story is that Laravel or whatever framework they used has a dangerous footgun that can easily lead to exposing secrets.
- ipaddr 4y agoA show debug info environment file flag? What would you replace it with? Two flags?
- quelltext 4y agoThe article states: > The environment configured on the live site was actually set to production, but the configuration also has APP_DEBUG=true set which is why a 500 server error response was giving such neat and useful output. It should be easy to add additional safeguards / warnings to prevent this combination from being set.
- ceejayoz 4y agoLaravel's debug mode [has a big warning in the docs about this](https://laravel.com/docs/9.x/configuration#debug-mode https://laravel.com/docs/9.x/configuration#debug-mode), defaults to off, and newer versions of Laravel use a different error module that doesn't show env vars.
- quelltext 4y ago> In your production environment, this value should always be false. If the variable is set to true in production, you risk exposing sensitive configuration values to your application's end users. It's still a footgun. It's pretty clear that this shouldn't be done, so why allow it this easily? In prod it should emit a log message saying "you cannot do that. if you really, need to follow these steps: <something cumbersome like placing a file somewhere with some dedicated end date for debug mode, or scoping rules>"
- jhugo 4y agoI don't know if this really counts as a "footgun". Exposing secrets is exactly what I would expect enabling debugging mode in production to do.
- SnowHill9902 4y agoSome secrets could be never printed and instead be redacted. Why would you need to print a full key?
- ceejayoz 4y agoIt’s just a .env file with key/value pairs. How is it supposed to know what’s a key and what isn’t?