Allintext Username Filetype Log Password.log Paypal
Periodically run the very dorks that attackers use against your own domains. Use the search query site:yourdomain.com ext:log to see what Google has indexed. If you find sensitive files, remove them from the server immediately and request their removal from the search index via Google's Search Console (the "Remove URL" tab).
This specific "dork" is designed to look for log files containing account credentials: allintext username filetype log password.log paypal