Skip to main content

Github Search Exposes Passwords

posted onJanuary 25, 2013
by l33tdawg

From the 'If you leave the keys out in the open it's your own fault' files:

Github rolled out a new search tool today making it easier to not just discover new projects, but code within projects. Think Google Code search (when it was alive, but better).

So the TL;dr version is – awesome power. But as Spiderman taught me a long time ago, with great power comes great responsibility. My friend and all around beacon of bodacious knowledge Carla Schroder (@CarlaSchroder) pointed out to me that there is no shortage of embedded private SSH keys and passwords that can easily be found. This is a problem that a few people have now noticed and a simple search can easily pull up more results than I care to count.

Source

Tags

Security Github

You May Also Like

Recent News

Wednesday, May 8th

Tuesday, May 7th

Monday, May 6th

Friday, May 3rd

Thursday, May 2nd

Wednesday, May 1st

Tuesday, April 30th