Your db Passwords Are Belong To Us.

Discussion in 'Google' started by geoiss2004, Oct 18, 2006.

  1. #1
    Google opened up a new search sevice called Google Code Search today. The new search allows you to search through a huge index of code that the Google search engine has crawled over the years.

    Being the curious beings we are, a friend of mine and I immediately started searching for passwords to see just how much Google was indexing. It didn’t turn up much in the way of anything “secret” until we refined our search to just wp-config files (the file that contains the database connection information for Wordpress installs).

    That worked. Since Google Code Search actually indexes the contents of compressed files like ZIP and TARBALL files, we were able to find copies of people’s wp-config files and several contained usernames and passwords.

    Here’s an example search.

    Now, this only pulls up 50 results (after filtering out the sample config files), but we only looked for Wordpress config files. Who knows what other similar files out there are being indexed and made public. So, a lesson to webmasters– don’t put anything you don’t want seen in a zip file on your server. Perhaps obvious to most, but worth repeating.

     
    geoiss2004, Oct 18, 2006 IP
  2. jackslounge

    jackslounge Peon

    Messages:
    434
    Likes Received:
    11
    Best Answers:
    0
    Trophy Points:
    0
    #2
    I got nothing when I clicked your link, but that is scary nonetheless..
     
    jackslounge, Oct 18, 2006 IP
  3. onedollar

    onedollar SEO Consultant for Hire

    Messages:
    3,481
    Likes Received:
    333
    Best Answers:
    0
    Trophy Points:
    0
    #3
    doesn't give any results here
     
    onedollar, Oct 18, 2006 IP
  4. T0PS3O

    T0PS3O Feel Good PLC

    Messages:
    13,219
    Likes Received:
    777
    Best Answers:
    0
    Trophy Points:
    0
    #4
    T0PS3O, Oct 18, 2006 IP
  5. sachin410

    sachin410 Illustrious Member

    Messages:
    6,422
    Likes Received:
    573
    Best Answers:
    0
    Trophy Points:
    410
    #5
    Remove the user part and then search.
     
    sachin410, Oct 18, 2006 IP
  6. abiji

    abiji Active Member

    Messages:
    467
    Likes Received:
    7
    Best Answers:
    0
    Trophy Points:
    78
    #6
    Thanks sachin it worked now.
     
    abiji, Oct 18, 2006 IP
  7. geoiss2004

    geoiss2004 Guest

    Messages:
    1,454
    Likes Received:
    32
    Best Answers:
    0
    Trophy Points:
    0
  8. Imran

    Imran Notable Member

    Messages:
    2,340
    Likes Received:
    190
    Best Answers:
    0
    Trophy Points:
    230
    #8
    Imran, Oct 18, 2006 IP
  9. sachin410

    sachin410 Illustrious Member

    Messages:
    6,422
    Likes Received:
    573
    Best Answers:
    0
    Trophy Points:
    410
    #9
    I think it is an installation and a trial password. (zip file)
     
    sachin410, Oct 18, 2006 IP
  10. yfs1

    yfs1 User Title Not Found

    Messages:
    13,798
    Likes Received:
    922
    Best Answers:
    0
    Trophy Points:
    0
    #10

    His signature would block it anyway ;)
     
    yfs1, Oct 18, 2006 IP
    T0PS3O likes this.