Updated
Updated · Fox News · Aug 25
Pageloot Finds Staging Credentials in Google Search Autocomplete After Google Doc Was Shared by Link
Updated
Updated · Fox News · Aug 25

Pageloot Finds Staging Credentials in Google Search Autocomplete After Google Doc Was Shared by Link

2 articles · Updated · Fox News · Aug 25

Summary

  • Pageloot discovered a staging hostname and apparent credential string in Google Search autocomplete after a contractor stored login details in a Google Doc accessible to anyone with the link.
  • The company traced the exposure to a broadly shared Docs URL that The Register said had been indexed by Google Search, then revoked the contractor's access and rotated the exposed credentials.
  • Google said Docs are Restricted by default, while files set to Anyone with the link can be opened by anyone who gets the URL; publicly shared links may also be indexed if posted where crawlers can find them.
  • Pageloot also reported a separate access failure in which a former employee's unrevoked credentials let a retailer's QR codes redirect shoppers to a competitor, underscoring the need to remove stale access.

Insights

How did a simple autocomplete search inadvertently expose a tech company's secure staging credentials to the public web?
Are the collaboration tools your team uses daily secretly acting as ticking time bombs for devastating data breaches?
Could your former employees still hold the digital keys to silently hijack your business traffic today?