WordPress base configuration files on GitHub
github.com
github.com
Absolutely, Github public repos have always been a blackhat gold mine. But I guess a lot of people have never heard of Bitbucket, since Github is advertised everywhere , on education blogs, books , ... I'm sure some noobs using it don't even realize repositories are public and searchable.
I love GH, but I only use it for my public projects. Limiting private repos ($200 for 125?) seems insane to me, and it will drive people to make public items that shouldn't be.
For any private projects, or ones involving clients, I use BitBucket and make all repos private. It's a difference of $190 for me (I use the $10/mth plan with BB and host well over 125 private repos).
But that's not really github's fault for people having public repos. For $20/month I can setup a VPS with my own source code hosting service (full management like gitlab) and host all the repos I want. I get people love the features of github - but they never really use them.
I would say people use public repos on github because they are lazy. And when people get nailed for uploading their Amazon AWS keys - they should really think about an alternative solution for their git repo needs.
https://github.com/search?p=1&q=filename%3Awp-config.php+DB_...
Uh, the concept of localhost is not unique to Wordpress in the slightest.
Store credentials in environment variables.
If the organization is "closed" by default, i.e. it only rarely releases code to the public, this may not matter as much.
Even if it's just 0.1%, that would be still 150'000 valid passwords.
Pertinent config globals are FTP_BASE, FTP_CONTENT_DIR, FTP_PLUGIN_DIR, FTP_PUBKEY, FTP_PRIKEY, and of course, FTP_USER, FTP_PASS, FTP_HOST.
https://github.com/search?utf8=%E2%9C%93&q=filename%3Aweb.co...
[0]: https://www.google.co.in/search?q=inurl%3Afilezilla+inurl%3A...
Github search is an untapped resource just like Algolia Search is on Hackernews. Infact I have largely replaced my Google searches with these ones for more refined and curated results.
1.) Password will be changed
2.) Possible honeypot
3.) Boring site is boring. No need to hack it. Not popular enough
Same goes for other databases on there. An enormous amount of cruft to wade through to get anything remotely juicy/interesting. And the same heuristics apply above: is it really so great that I logged into a boring MYSQL database that is probably being monitored and has nothing interesting in there in the first place?
filename:"wp-config.php" "define('DB_NAME'," extension:php
seems to give better resultsIt just takes more time.
Indeed.
> that suggests otherwise:
Except that it does no such thing. If you have passwords for defense in depth, they both exist for security reasons and it is a security problem to expose them (because you've just eliminated part of your depth.)
Defense in depth means that the problems of any one layer being violated are mitigated by additional layers of security, it doesn't mean it suddenly ceases to be a security problem if one of your measures is compromised. It just reduces the likely immediate severity of such a compromise, providing a greater chance of being able to effectively address it before it leads to an actual breach.
Yes, it's still a problem, because then you have to depend on the whitelist staying valid and never having an admin accidentally turn it off. And you also have to depend on none of the machines on the trusted IPs being compromised either. And you have to depend on many other things not happening as well.
Instead, you want what is called defense in depth--several layers of security so that an attacker needs to breach several defensive layers in order to get access to what they're looking for. Relying on just an IP whitelist as a single layer of defense is not considered to be a good practice.
https://github.com/search?utf8=%E2%9C%93&q=filename%3Asettin...
I feel like people don't accept the fact that people do stupid stuff in other languages.
Wordpress, and by extension, its predictably-named settings file, is an easy search-target because it's very popular among novice/new developers.
I'm just tired of seeing the same search on github for PHP config files.
> its predictably-named settings file
So does every other popular application and framework on the planet. This isn't something specific to wordpress - we can play this game all day with different applications, frameworks, and languages.
https://github.com/search?q=mysql+user&type=Code&utf8=%E2%9C...
!!! How many of them use the same credentials for their emails ? facebook ? twitter ? for their AWS account ? this is a nightmare.
Regards