Link Love - October 24
Security oversights & more
For today's link love, I want to showcase a little security oversight that gives me a chuckle.
In a ruby on rails app, there is a yml file that declares all the database connection info. It is typically stored in the /config/database.yml folder. Now if a rails app is properly set up, this folder is never publically accessible.
But some people are idiots, as we all know.
Bonus points go out to the person who can figure out the google query that turns up database.yml files :)
OK, that was fun. What else do we have here today......
Going one step beyond the View Source Tool I linked to yesterday, today I want to show you the SEO Text Browser. This little tool returns some salient SEO information for the target URL plus its content. Annnnnnnd.....wait for it.......it follows redirects.
DabbleDB is really cool. I used to work with a lovely young lady who's partner is one of the lead guys on that project. Last I heard they were digging around for some VC funding...I dont know if they ever got it, but regardless, DabbleDB is very very cool. This project is pretty ground breaking in my opinion, and has serious implications for the way data is stored, gathered, and shared on the intertube.
Check out this DabbleDB application of XSS Vectors
There's your link love for the day! Enjoy!
Back
Comment:
-"View source" -intitle:browsing inurl:config/database.yml -inurl:svn -inurl:trunk -inurl:example filetype:yml "adapter:" "database:" "host:" "username:" "password:"
you can try to paly with it to get more results... i tried to remove all these svn, must of them don't have a password in them
enjoy
Comment: Nice job man! Thanks for sharing.
Announcements & News 14 Posts
General news relating to this site
Google Hacking 9 Posts
Oh, the treasures that are to be found on Google!
Links & Points of Interest 9 Posts
Links of interest
Technical 14 Posts
Scripts, Programming, Advanced SEO Techniques
Theory 23 Posts
Off the top of the dome...
Tools & Applications 5 Posts
Tools to help you grow your empire
Twitter 6 Posts
Anything and everything having to do with Twitter
Website Development 4 Posts
Principals and Best Practices for general web development
recent comments:
nickycakes on I Could Be Anythingabdul on An open letter to all my Friends across all Social Networks.
Musashi on Fun with String Permutations
Rob on An Introduction to Datapresser's Content Generator
stack paper on An Introduction to Datapresser's Content Generator
stack paper on An Introduction to Datapresser's Content Generator
big man on Dude, where's my proxy?!?!
5ubliminal on Stuffing website inputs: A technique for gaining backlinks.
abdul on Stuffing website inputs: A technique for gaining backlinks.
Paul on An Introduction to Datapresser's Content Generator
Subscribe to Recent Posts
Subscribe to Featured Databases
Subscribe to Free Downloads
