Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Don’t keep backups on your web server, even if you think they’re secret (petdance.com)
5 points by ohjeez on Aug 23, 2018 | hide | past | favorite | 1 comment


> Today I was looking through the error log for a website I work on and noticed a series of 404s, where someone at the same IP address in China was asking for files that didn’t exist.

Chinese origin is irrelevant; the behavior described in the article is baked into every commodity vulnerability scanner on the market these days.

Other target variants include permutations of (backup|sql|sqldump|dump)\.(sql|7z|tar|tar\.gz|gz|rar) expected to be found in the local directory, as well as *.pem, your raw /.git/ directory and lots more.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: