Salutations -- I write not as another spammer talking of riches and fame but as a concerned cybersecurity student aspiring to be a graduate. YOUR OPENSSH PRIVATE KEY WAS COMPROMISED IN A GOOGLE DORK IN CASE YOU WERE NOT AWARE! I figure that now that the important part was stated, I should share some proof of it. Attached will be a series of two (2) images. These were stumbled across while I was completing an assignment for my college course. I only wanted to share the information with you considering I figured it'd be pertinent for something like this.
ball drinker <bipperdipper0@gmail.com> writes:
Salutations -- I write not as another spammer talking of riches and fame but as a concerned cybersecurity student aspiring to be a graduate.
YOUR OPENSSH PRIVATE KEY WAS COMPROMISED IN A GOOGLE DORK IN CASE YOU WERE NOT AWARE! I figure that now that the important part was stated, I should share some proof of it. Attached will be a series of two (2) images. These were stumbled across while I was completing an assignment for my college course.
I only wanted to share the information with you considering I figured it'd be pertinent for something like this.
Hi, thanks for your concern, but this is not an issue. Note that the key you have found is inside a directory called "tests" in Nixpkgs, and is named "snake oil". It is a test fixture, not a key that controls access to anything outside of that test. I imagine by now you'll have found that this key exists in many places across the web, wherever there are copies of Nixpkgs. The enthusiasm is nice, but please make sure to check thoroughly before reporting security issues — not every instance of a pattern is automatically an issue, and if it looks like you haven't done this checking, your reports are likely to be seen as spam after all. Maintainers are frequently burdened with people submitting reports from automated security scanners that are not identifying real issues, and are quite likely to filter out anything that looks like that. Good luck with your course!
participants (2)
-
Alyssa Ross -
ball drinker