Area: Exposed infrastructure
Indexed content
Searches the Common Crawl index and, if available, Brave Search for addresses of your domain that point to backups and data dumps, logs, code repositories, configuration files, sign-in or admin panels, API documentation, directory listings or internal documents. It only queries those sources (the search engines, not your server): it doesn't open any of those addresses or try others.
What it can report
Open each one to see what it means and how to fix it.
Sensitive addresses in a public web archive
What it means
What could happen
How an attacker would use it
How to fix it
- Check, in your hosting file manager, that those files no longer exist, and delete them if they do.Ask your host or IT person if you're not sure how.
- Work out what each file contained: customer data, passwords or just pages.
- If it held passwords or keys, change them: website admin, database and any integrations.
- From now on, keep backups outside the public part of the website.
- If personal data was in the file, ask a lawyer whether you must notify anyone.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.
Internal-looking documents in a search engine
What it means
What could happen
How an attacker would use it
How to fix it
- Open those documents from your side and check whether they are public on purpose.
- Take down the ones that aren't, or protect them with a password, and tell the search engine to forget them.
- Check where the file is stored: your website's uploads folder is public by default.
- If personal data was exposed, ask a lawyer whether you must notify the people involved.
How to check it's fixed
Who usually fixes it
Example with sample data. In your dashboard, the explanation uses your own domain and details.