To be fair, I bet there are a lot of things like that out there, along with folk using “password1” as their login.
…but it felt like a bit of let down in the story.
1) Get shell access!
2) look for a commit entitled “root key here”
3) profit!
I was a bit disappointed, I was hoping for some exploit… but I guess often this stuff is just mundane human failures.
…also, is it fine to only partially redact a private key in an image?
I mean, tell me I’m wrong here, but isn’t that kinda bad? (Maybe it’s just a mock image for the post, who knows).