develwoutacause’s avatardevelwoutacause’s Twitter Archive—№ 1,176

  1. …in reply to @SushiHack
    @SushiHack I once found a database username and password in plaintext in an #HTML comment. Not a "stripped by the rendering engine" comment either, it was visible in view-source. Bonus points for being on the company's internal *home page*, not some random document.