docs: redact plaintext admin passwords from git audit reports
This commit is contained in:
@@ -144,9 +144,9 @@ This gives every file a clear home without over-nesting.
|
||||
#### `scripts` — 10 potential secrets
|
||||
Real, hardcoded credentials found in Windows provisioning scripts:
|
||||
```
|
||||
+Password="LoveMyBoys73!"
|
||||
+Password="Liberty4All!"
|
||||
+Password="tire"
|
||||
+Password="[REDACTED]"
|
||||
+Password="[REDACTED]"
|
||||
+Password="[REDACTED]"
|
||||
+Username="ippadmin"
|
||||
+Username="liberty-admin"
|
||||
```
|
||||
@@ -156,10 +156,10 @@ These are active Windows admin credentials embedded in PowerShell unattend scrip
|
||||
#### `hermes-recovery` — 8 potential secrets
|
||||
Includes the Gitea API token used for this audit:
|
||||
```
|
||||
+TOKEN="1761daa2c537fb72b365e54619208329d8e3ad33"
|
||||
+TELEGRAM_BOT_TOKEN="8359374835:***"
|
||||
+password="K3E1ZZWvHDu0q8ZmoBCAhzKUZawEapdGBlbaPME1sOTKgGk9FCuYS"
|
||||
+token = "Ta9f9d1b462271a2f4-8d63a3f025eb89451edb16f2308c2e40"
|
||||
+TOKEN="[REDACTED]"
|
||||
+TELEGRAM_BOT_TOKEN="[REDACTED]"
|
||||
+password="***"
|
||||
+token = "[REDACTED]"
|
||||
```
|
||||
|
||||
The Gitea token itself is committed. This means `hermes-recovery` as a public repo exposes admin credentials.
|
||||
|
||||
Reference in New Issue
Block a user