Web Designer

October 11, 2006

Protect your website from Google Code Search

Filed under: Freelancers Talk — Zaur @ 4:07 pm

It has come to our attention that Google has released a new product, Google Code Search, that is capable of indexing and crawling through archive files stored in the public directories of web servers. This is security advisory becauseĀ I have discovered that some site administrators are storing archives / backups of their website in the web root. Because of this, Google Code Search is able to crawl the archives and read unparsed PHP files as if they were plain text. This has resulted in the disclosure of some sensitive information including MySQL passwords and SMTP credentials.

No Comments »

No comments yet.

RSS feed for comments on this post. TrackBack URI

Leave a comment

2006 © Web Designers Blog at web.pdesigner.net