DEV Community

Discussion on: Please don't commit .env

Collapse
 
somedood profile image
Basti Ortiz

You could always show them a demo of the amount of damage you can do if you had access to that "small" .env file. I'm sure they'll be alarmed after that.

Collapse
 
tadman profile image
Scott Tadman

Be very careful when doing this as some wildly misguided company may accuse you of hacking and try and prosecute.

Thread Thread
 
somedood profile image
Basti Ortiz

I'm sure he'll be informing them about the demo beforehand. 😉

Thread Thread
 
bauripalash profile image
Palash Bauri 👻 • Edited

@somedood , Yes Yes!

Collapse
 
bauripalash profile image
Palash Bauri 👻

Will Do.

I've seen many juicy leaks there such as Google Cloud Platform Keys , Facebook Credentials , GitHub Credentials and even someone's phone number 😂

Thread Thread
 
somedood profile image
Basti Ortiz

Hack responsibly! 😉

Thread Thread
 
bauripalash profile image
Palash Bauri 👻

Just Proof-Of-Concept 😄