For everyone else: Do not store passwords in logs. Do not upload logs to public web roots. And if you see this dork in your server logs, know that a security researcher is likely doing you a favor—whether you asked for it or not.
Add this to /robots.txt :
Elias sat back, the adrenaline crashing. He had destroyed the data, but he hadn't fixed the hole. The server was still open. allintext username filetype log passwordlog facebook fixed