Configure your sites right!

We live in a modern age, but unfortunately, even in such a modern age, you can still easily dowload database exports with just a simple google search. From simple contact me form records to school databases, there is no shortage of exposed databases, available for anyone to snoop and mess around with it. And what do people do when they get access to such thing? Well, they will probably use it for malicious purposes.

Well, how easy is it?

Here is how to do it in a few short and simple steps

  1. Go to Google
  2. Search: intext:"index of" ".sql"
  3. ???
  4. profit

It's concerningly easy to do such an "attack". My grandma could probably do it.

Soooooo, is it only .sql files?

No. Here are a few of my favourites

  1. Laravel: intext:"index of" "artisan" ".env"
  2. Pictures: intext:"index of" ".png"
  3. Videos: intext:"index of" ".mp4"(found some really cute cat videos with this one)

It's 2023. Configure your websites properly.

To companies: paying a sysadmin to deploy your site properly will pay off.

Hall of shame

The database passwords that are just horrible