DefectiveCISO on Nostr: chasing ghosts in ir while the db creds were sitting in world-readable config.xml the ...
chasing ghosts in ir while the db creds were sitting in world-readable config.xml the whole time. fixes half my old breach scars just reading this.
> One of the most common post-compromise wins is finding sensitive configuration files left readable on disk. Web applications, internal tools, and backend services often store database hosts, usernames, API endpoints, SMTP credentials, and secret keys in plain text configuration
— @Officialwhyte22
#cybersecurity #infosec #news #incident
https://x.com/Officialwhyte22/status/2037775443198198109Published at
2026-03-28 13:02:40 UTCEvent JSON
{
"id": "bd21e3d8125cb43545bb86e83decfdd9c639978a94a430493e5c9f889ca08a51",
"pubkey": "c515131657f13f4486cff1b6078a0f2ad3d083acd0c2bf46b192a33f8f80efc8",
"created_at": 1774702960,
"kind": 1,
"tags": [
[
"imeta",
"url https://image.nostr.build/3a41b2bec6e33ffaf32189e3479aa5fdfe2dd3d4c7b4137ab9960d19e3576d39.jpg"
],
[
"t",
"cybersecurity"
],
[
"t",
"infosec"
],
[
"t",
"news"
],
[
"t",
"incident"
],
[
"r",
"https://x.com/Officialwhyte22/status/2037775443198198109"
],
[
"source",
"x.com"
]
],
"content": "chasing ghosts in ir while the db creds were sitting in world-readable config.xml the whole time. fixes half my old breach scars just reading this.\n\n\u003e One of the most common post-compromise wins is finding sensitive configuration files left readable on disk. Web applications, internal tools, and backend services often store database hosts, usernames, API endpoints, SMTP credentials, and secret keys in plain text configuration\n— @Officialwhyte22\n\nhttps://image.nostr.build/3a41b2bec6e33ffaf32189e3479aa5fdfe2dd3d4c7b4137ab9960d19e3576d39.jpg\n\n#cybersecurity #infosec #news #incident\nhttps://x.com/Officialwhyte22/status/2037775443198198109",
"sig": "59691fdef1724e6cde94bfc9c253b629184ac52770dbfd98a3548e42891302c20fc415944aec33669ed837c95d8a22b1856d433463379de0b8a3f1b71cb843af"
}