spansh / edsm-export

0 stars 0 forks source link

Plaintext password in file. #1

Closed neenjaw closed 4 years ago

neenjaw commented 4 years ago

Hello @spansh!

Just trying to learn about your neutron star plotter and I found this repo to learn from your approach. While looking through, I did notice that you have committed a plaintext password here: https://github.com/spansh/edsm-export/blob/dd1651b057290745070aeac9fa158c2b9ee8b079/export.pl#L179

This is for localhost connect, but it seems like this is a real password somewhere. Anyway, just a headsup!

spansh commented 4 years ago

Thanks very much for the heads up, I was made aware of it shortly after it got uploaded. As it was uploaded at any time and it was only a localhost password I changed the relevant passwords quite some time back (even though the database isn't exposed externally).

Always worth checking it though, so thankyou.

On Fri, 18 Sep 2020 at 05:58, Tim Austin notifications@github.com wrote:

Hello @spansh https://github.com/spansh!

Just trying to learn about your neutron star plotter and I found this repo to learn from your approach. While looking through, I did notice that you have committed a plaintext password here: https://github.com/spansh/edsm-export/blob/dd1651b057290745070aeac9fa158c2b9ee8b079/export.pl#L179

This is for localhost connect, but it seems like this is a real password somewhere. Anyway, just a headsup!

— You are receiving this because you were mentioned. Reply to this email directly, view it on GitHub https://github.com/spansh/edsm-export/issues/1, or unsubscribe https://github.com/notifications/unsubscribe-auth/AAAZGKE7Y2PVN7ATCVD2REDSGLSIHANCNFSM4RRNRMUQ .