Hacker News new | ask | show | jobs
by amarcus 4976 days ago
You think this is bad. Try doing the following google search:

"password" filetype:csv

3 comments

I'm sure lots of people have had unwanted encounters with Google's crawlers, but here's mine: I used to have a subdomain pointing to my home IP which was protected using Apache htpasswd. I naively had all of my clients' credentials stored in text files (conveniently named credentials.txt). Somehow I accidentally removed the htpasswd authentication and it was publicly exposed for a day or two. Of course Google indexed it and you could view everything in Google's cache.

There was a process for removing content from Google, but it took a few months to get completed. I never told anyone and I'm pretty sure all that info is now purged (I've tried to find it multiple times and it doesn't seem to exist anywhere).

I also downloaded a WoW guide that I had temporarily thrown up on one of my servers and forgot to take down. Like a year later I randomly was running a Google image search for 'Northrend Map' and happened to notice my site was the THIRD image. At first I thought it was a personalized search result, but I checked from multiple other places and it was still there even though there were zero inbound links.

this is an entire category of attack, and it is really useful. there have been a number of worms that use google queries to find targets to propagate.

there are also a number of info query tools that do similar.

over 3000+ Google queries categorized in exploit-db:

http://www.exploit-db.com/google-dorks/

But it is not about facebook users.