TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Tell HN: Coca-Cola staging servers are showing up in search results

19 pointsby cryptoz9 months ago
See for example, https:&#x2F;&#x2F;www.google.com&#x2F;search?q=cherry+coke<p>gives you a top result of https:&#x2F;&#x2F;staging.us.coca-cola.com&#x2F;products&#x2F;coca-cola-energy&#x2F;cherry<p>which prompts with like an htaccess password

9 comments

lbhdc9 months ago
I got a different staging server as my #2 result. This is password pretected like OP suggested. <a href="https:&#x2F;&#x2F;preview.us.coca-cola.com&#x2F;products&#x2F;coca-cola-flavors&#x2F;cherry-vanilla" rel="nofollow">https:&#x2F;&#x2F;preview.us.coca-cola.com&#x2F;products&#x2F;coca-cola-flavors&#x2F;...</a><p>The link OP shared is open to the public to me. <a href="https:&#x2F;&#x2F;staging.us.coca-cola.com&#x2F;products&#x2F;coca-cola-energy&#x2F;cherry" rel="nofollow">https:&#x2F;&#x2F;staging.us.coca-cola.com&#x2F;products&#x2F;coca-cola-energy&#x2F;c...</a><p>I would think that even if these weren&#x27;t showing up on google that people would be able to find the subdomains through dns. They should probably move these to an internal domain so they are harder to find.
denysvitali9 months ago
For me the same happens w&#x2F; Netflix: their staging environment just shows up in normal search results: <a href="https:&#x2F;&#x2F;www.release.staging.ssic.netflix.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.release.staging.ssic.netflix.com&#x2F;</a>
GauntletWizard9 months ago
I see it, but I don&#x27;t see a password; It looks just like the live site to me. <a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Zn9tHCk" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;Zn9tHCk</a>
uaas9 months ago
This applies to most big companies, maybe you just happened to notice it now. Security researchers are leveraging these (called Google dorks) every minute to find targets.
doormatt9 months ago
Top result for me is <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Coca-Cola_Cherry" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Coca-Cola_Cherry</a>
评论 #41314954 未加载
daemonologist9 months ago
Yep I see it, though it doesn&#x27;t prompt me for a password - just looks like a normal half-finished website (although very different from www.coca-cola.com). Interesting.
Raed6679 months ago
&gt; Coca-Cola® Energy Zero Sugar<p>&gt; Calories 0<p>&gt; Coca-Cola® Energy Zero Sugar combines the great taste of Coca-Cola with the energy you want to power you
评论 #41321564 未加载
mikequinlan9 months ago
So what is the username and password?
评论 #41315035 未加载
ipaddr9 months ago
The footer has a 2021 copyright.