I am not sure how sensitive the information you have in your auth database is, but /etc/libnss-mysql.cfg on shell.sf.net is world-readable with a password exposed:
[server]
host ldap
database auth
username nss-user
password 9d1jd899y3hs2.
2007-01-19 21:39:45 UTC in SourceForge.net