23

So.. tons of sites have their Laravel .env file accessible...

Google this: filetype:env APP_ENV

Comments
  • 3
    This is nothing, google dorks will turn google into a vulnerable website candy store.

    exploit-db.com // pick your favorite exploit disclosure, alot of the reports contain the dork (query) to find vulnerable websites.
  • 0
  • 0
    Woah
  • 2
    I'm not big fan of any env files, I have a file called `env.ini.php`
  • 1
    Map your base path to the public folder folks, it's not hard
  • 1
    Inexcusable :/
  • 0
    Not just laravel, popular for nodejs as well
  • 0
    @macleod Really? Most node webapps only serve the public asset directory, and the env file should not there .-.
Add Comment