<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>froztbyte.getBlog() &#187; information leakage</title>
	<atom:link href="http://blog.froztbyte.net/tag/information-leakage/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.froztbyte.net</link>
	<description>returns the contents of froztbyte.blog</description>
	<lastBuildDate>Mon, 13 Oct 2014 20:19:25 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=4.0</generator>
	<item>
		<title>Retardville</title>
		<link>http://blog.froztbyte.net/2013/01/retardville/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=retardville</link>
		<comments>http://blog.froztbyte.net/2013/01/retardville/#comments</comments>
		<pubDate>Thu, 24 Jan 2013 14:30:04 +0000</pubDate>
		<dc:creator><![CDATA[froztbyte]]></dc:creator>
				<category><![CDATA[rage]]></category>
		<category><![CDATA[roflcakes]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[hanlon's]]></category>
		<category><![CDATA[information leakage]]></category>
		<category><![CDATA[mistakes]]></category>

		<guid isPermaLink="false">http://blog.froztbyte.net/?p=362</guid>
		<description><![CDATA[Update: I&#8217;ve contacted Github support about this, and given them a suggestion about a default-on preference/setting to filter those for everyone but the repo owner, perhaps with a visual cue about it Update 2: as of this update, the search &#8230;<p class="read-more"><a href="http://blog.froztbyte.net/2013/01/retardville/">Read more &#187;</a></p>]]></description>
				<content:encoded><![CDATA[<p><strong>Update</strong>: I&#8217;ve contacted Github support about this, and given them a suggestion about a default-on preference/setting to filter those for everyone but the repo owner, perhaps with a visual cue about it</p>
<p><strong>Update 2</strong>: as of this update, the search for these sorts of files no longer appears to be working; I also got a mail back from github support about this earlier, but didn&#8217;t really read it yet</p>
<p>Or to give people the benefit of the doubt, perhaps they just didn&#8217;t know better. I don&#8217;t even understand how this comes to pass, it&#8217;s so different from what I&#8217;m typically used to.</p>
<p><a href="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards.png"><img class="alignnone size-full wp-image-363" title="SSH Keys" src="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards.png" alt="github ssh keys" width="1125" height="648" /></a></p>
<p><a href="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards1.png"><img class="alignnone size-full wp-image-364" title="Bash History" src="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards1.png" alt="github bash history" width="1125" height="648" /></a></p>
<p><a href="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards2.png"><img class="alignnone size-full wp-image-365" title="Zsh History" src="http://blog.froztbyte.net/wp-content/uploads/2013/01/neckbeards2.png" alt="github zsh history" width="1125" height="648" /></a></p>
<p>&nbsp;</p>
<p>The URLs for these are as follows:</p>
<ul>
<li>https://github.com/search?q=path%3A.bash_history</li>
<li>https://github.com/search?q=path%3A.zsh_history</li>
<li>https://github.com/search?q=path%3A.ssh/id_rsa</li>
</ul>
<div><span style="line-height: 18px;"><span style="line-height: 18px;">There are some more, obviously. Use your imagination to find them. You can also filter for passwords and such:<br />
</span></span></p>
<ul>
<li>https://github.com/search?q=path%3A.bash_history+password</li>
<li>https://github.com/search?q=path%3A.my.cnf</li>
</ul>
</div>
<p>So, to all the people who have done this: <span style="text-decoration: underline;"><strong>don&#8217;t upload any of your history files, private ssh keys, etc, to something on the public internet.</strong></span></p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.froztbyte.net/2013/01/retardville/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
