Security News > 2015 > March > The hacker first uploaded a file, class.php .. The database credentials WERE in a non-www accessible directory, however, anyone smart enough can find the include lines .. Then, he uploaded adminer.php a web based database management tool . I (Reddit)