A few days ago on 25th April, while researching, I found that a lot of individuals and companies are putting their sensitive information on their public Trello boards. Information like unfixed bugs and security vulnerabilities, the credentials of their social media accounts, email accounts, server and admin dashboards — you name it, is available on their public Trello Boards which are being indexed by all the search engines and anyone can easily find them. How did I discover this? I searched for Jira instances of companies running Bug Bounty Programs with the following search query: inurl:jira AND intitle:login AND inurl:[company_name] Note: I used a Google dork query, sometimes referred to as a dork. It is a search string that uses advanced search operators to find information that is not readily available on a website. — WhatIs.com I entered Trello in place of [company name]. Google presented a few results on Trello Boards. Their visibility was....
This is a really amazing piece of writing. There are things that I come to know for the first time and I wanna give thank you for sharing the information.