[GH-ISSUE #345] Sensitive data #223

Closed
opened 2026-02-25 20:33:06 +03:00 by kerem · 3 comments
Owner

Originally created by @fedeisas on GitHub (Apr 2, 2019).
Original GitHub issue: https://github.com/asciinema/asciinema/issues/345

I tried to get in touch with @sickill but couldn't find an email anywhere and couldn't get a response in Twitter.

I used to work for a company some years ago, I used asciicinema to share a session with a coworker without really thinking about the security implications of it. That session ended up showing up here.

While it doesn't leak any credentials, it does show sensitive information about the app tech stack, database, etc.

I don't seem to even have an account on https://asciinema.org/ (maybe I was using my work email?).

Does anyone knows @0xbzho?

Originally created by @fedeisas on GitHub (Apr 2, 2019). Original GitHub issue: https://github.com/asciinema/asciinema/issues/345 I tried to get in touch with @sickill but couldn't find an email anywhere and couldn't get a response in Twitter. I used to work for a company some years ago, I used asciicinema to share a session with a coworker without really thinking about the security implications of it. That session ended up showing up [here](https://github.com/0xbzho/asciinema.org-2015-03/). While it doesn't leak any credentials, it does show sensitive information about the app tech stack, database, etc. I don't seem to even have an account on https://asciinema.org/ (maybe I was using my work email?). Does anyone knows @0xbzho?
kerem closed this issue 2026-02-25 20:33:06 +03:00
Author
Owner

@cyc115 commented on GitHub (Apr 10, 2019):

Either way I think it would be good for @oxbzho to take it down if it include private uploads and find out why it was there in the first place.

<!-- gh-comment-id:481803353 --> @cyc115 commented on GitHub (Apr 10, 2019): Either way I think it would be good for @oxbzho to take it down if it include private uploads and find out why it was there in the first place.
Author
Owner

@fedeisas commented on GitHub (Apr 10, 2019):

Seems like a ghost account. I contacted @github about it but they refuse to take it down.

<!-- gh-comment-id:481812731 --> @fedeisas commented on GitHub (Apr 10, 2019): Seems like a ghost account. I contacted @github about it but they refuse to take it down.
Author
Owner

@ku1ik commented on GitHub (Apr 11, 2019):

It seems they crawled asciinema.org and downloaded all public recordings back then (2015, 2016).

I don't know this user either.

<!-- gh-comment-id:481979445 --> @ku1ik commented on GitHub (Apr 11, 2019): It seems they crawled asciinema.org and downloaded all public recordings back then (2015, 2016). I don't know this user either.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/asciinema#223
No description provided.