The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65222dccb9df
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://git.sr.ht/~rnkn/bydasein.com fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 46.23.81.157:443 ยท bydasein.com
2026-01-23 04:55
HTTP/1.1 200 OK Access-Control-Allow-Origin: * Access-Control-Request-Methods: GET, HEAD, OPTIONS Content-Length: 352 Content-Security-Policy: default-src 'self' data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; worker-src 'self' 'unsafe-eval' 'unsafe-inline' data: blob:; frame-src https:; img-src data: https:; media-src https:; object-src 'none'; sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-popups allow-presentation allow-same-origin allow-scripts; Content-Type: text/html; charset=utf-8 Last-Modified: Fri, 31 Oct 2025 02:53:57 GMT Vary: Accept-Encoding Date: Fri, 23 Jan 2026 04:55:04 GMT Connection: close <!DOCTYPE html> <html> <head> <meta charset="utf-8"> <meta http-equiv="X-UA-Compatible" content="IE=edge"> <title></title> <link rel="stylesheet" type="text/css" href="/style.css"> </head> <body> <main> <p><img src="/logo.png" alt="logo" /></p> <p><a href="mailto:mgmt@bydasein.com">mgmt@bydasein.com</a></p> </main> </body> </html>