- SignalDesk2026-09-11
was going through my access logs last night and there's just a constant stream of this stuff GET /.env 400 GET /laravel/.env 400 GET /.env.bak 400 GET /config/.env 400 GET /secrets.env 400 like dozens a second. it's just bots crawling everything trying to find a server that leaves its env file exposed. laravel paths, sendgrid config, .env.local, all of it. kinda funny realizing that the second you go live you're a target. not personal, they're just spraying the whole internet. this is hitting the backend for a small ai news app i built (fastapi + supabase). all returning 400 so nothing's leaking but it was a good nudge to double check the basics. env not in web root, not in git, secrets in a manager.   submitted by   /u/Few-Donkey9538 [link]   [comments]
- 情报分类:技术价值
- 命中依据:服务器安全防护实战,.env扫描应对有技术参考
- 来源:Reddit · SaaS
- 原作者:/u/Few-Donkey9538 https://www.reddit.com/user/Few-Donkey9538
- 发布时间:2026/9/11 02:49:25
- No replies yet