Skip to main content

Github Search Exposes Passwords

posted onJanuary 25, 2013
by l33tdawg

From the 'If you leave the keys out in the open it's your own fault' files:

Github rolled out a new search tool today making it easier to not just discover new projects, but code within projects. Think Google Code search (when it was alive, but better).

So the TL;dr version is – awesome power. But as Spiderman taught me a long time ago, with great power comes great responsibility. My friend and all around beacon of bodacious knowledge Carla Schroder (@CarlaSchroder) pointed out to me that there is no shortage of embedded private SSH keys and passwords that can easily be found. This is a problem that a few people have now noticed and a simple search can easily pull up more results than I care to count.

Source

Tags

Security Github

You May Also Like

Recent News

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th