Scott Dutton

2.7K posts

Scott Dutton

Scott Dutton

@exusssum

Katılım Nisan 2009
335 Takip Edilen126 Takipçiler
Tanmay Das
Tanmay Das@TanmayMishu·
You invite a junior dev, they remove .env from .gitignore, and then run git push. Some people accidentally copy the content of .env to .env.example (typically while copying from production server to local machine) and forget to undo the changes in .env.example, and then run git push.
English
1
0
2
31
The Hacker News
The Hacker News@TheHackersNews·
🚨 260K Laravel APP_KEYs exposed on GitHub — over 600 apps vulnerable, and ~120 at immediate risk of remote code execution. With keys + URLs leaked, attackers can hijack servers via deserialization. Most devs likely unaware. Full story + what to do → thehackernews.com/2025/07/over-6…
English
9
81
190
65K
Scott Dutton
Scott Dutton@exusssum·
@julian_center @snapey @TheHackersNews Its really common to put real creds into .env.example. The linked CVE shows exactly that. Secrets used everywhere put into .env.example, build copys .env from .env.example
English
0
0
0
56
Remsio
Remsio@_remsio_·
Ever wondered if Laravel secrets used for encryption are usually correctly managed? Well, we made statistics from all the internet regarding this specific topic during an entire year and summed up everything in this blog post, Hope you enjoy it! 😁
Synacktiv@Synacktiv

🔐 Data encryption in Laravel environments is based on one secret: the APP_KEY. Our ninja @_remsio_ studied the impact of its leakage on the internet during an entire year. synacktiv.com/en/publication…

English
1
0
5
423
Tanmay Das
Tanmay Das@TanmayMishu·
@enunomaduro could this be within the scope of pest Arch Test? arch()->expectFile(‘.env’)->toBeGitIgnored(); Could be included in: arch()->preset()->security(); Those who will want to push the .env to VCS, will eventually push them anyway 🤦‍♂️, but might come in handy as a soft preventive measure
English
3
0
15
2K
Patricio
Patricio@PatricioOnCode·
@MrPunyapal 260k apps is a lot. I’m betting its apps being deployed to the /public folder in shared hosting environments, combined with lack of hosting experience
English
2
0
2
947
Scott Dutton
Scott Dutton@exusssum·
@alexellisuk Looks great. Out of interest why 3.5 turbo over 4o-mini. Mini usually gives better results for me and is cheaper
English
1
0
1
30
Alex Ellis
Alex Ellis@alexellisuk·
We've been seeing more and more cold emails getting through Google's spam filter.. so we took matters into our own hands with @openfaas and @OpenAI Link in next message..
Alex Ellis tweet media
English
2
1
5
1.2K
DC441244
DC441244@dc441244·
Hey Everone, we are very excited about the first meet up of the Chester Defcon group DC441244 next week on Thursday evening (3rd April 2025) at the City Tavern on Frodsham Street in Chester. The content will be excellent and the company even better. We can’t wait to see ya there!
English
1
3
7
1.9K
Scott Dutton retweetledi
Algebra Etc.
Algebra Etc.@AlgebraFact·
Algebra Etc. tweet media
ZXX
25
554
3.8K
153.2K
Scott Dutton
Scott Dutton@exusssum·
@theoboldalex /** @var MyObject[] */ Will work with tools like phpstan, not native but very good Can also wrap it in a new object with ArrayAccess implemented. not quite the same but works well
English
0
0
1
33
Matthew Mincher
Matthew Mincher@matthewmincher·
buying spools of pla has become my new sideproject domain registration
English
2
0
3
88
Scott Dutton retweetledi
Mark C.
Mark C.@LargeCardinal·
I have been laughing at this entirely too long...
Mark C. tweet media
English
23
653
5K
213.8K
Jonathan H. Wage
Jonathan H. Wage@jwage·
What’s the best setup for detecting dead code in @symfony? I tried to use @psalmphp but I got a ton of incorrect results from listeners and other things that do get used by the container.
English
5
0
3
679
Vaugen Wakeling
Vaugen Wakeling@vaugenwake·
Got a pack of NFC tags coming tomorrow. They about to be everywhere 😂😂
English
1
0
1
28