The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652212fd2bae
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = http://gitdeployment:GitDepL0yment@git.active18.com/platform/file18-desktop.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227e8ea600
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = http://gitdeployment:GitDepL0yment@git.active18.com/news18/english_cms.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [branch "master_multi_tenant"] remote = origin merge = refs/heads/master_multi_tenant
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c70ba7b5770ba7b57e0f1e2150dfa676f063053709bbbe54f
Found 54 files trough .DS_Store spidering: /; /allkeys.php /amazon-associate-dashboard /check-aws-redis.php /composer.json /composer.lock /copy-dc-to-cloud.php /crons /customs /db-config.php /digital-first /export-data.php /external /Fluid ROS Tags.txt /includes /index.php /license.txt /light_edit.php /migration /nbproject /News18-5xx-24hr.csv /predis /prj-prod-svc-news18-engb4-d33ad50b03ee.json /prj-stg-svc-news1847-1280cc5ebd0d.json /readme.html /redis-migrate-aws-key-wise.php /redis_cluster_dir /remove_tags_td.csv /save-redis.php /table.php /test-redis-value.php /test_redis.php /update_panni_redis_v2.php /update_sii_redis.php /user_update.php /vendor /wp-activate.php /wp-admin /wp-blog-header.php /wp-comments-post.php /wp-config-sample.php /wp-config.php /wp-content /wp-content_pushimp /wp-cron.php /wp-includes /wp-links-opml.php /wp-load.php /wp-login.php /wp-mail.php /wp-settings.php /wp-signup.php /wp-trackback.php /xmlrpc.php