.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c910c508a910c508a9652db29995f71f4d2b941683a4f5394
Found 55 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/database/factories /source/database/migrations /source/database/seeders /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /storage/app /storage/fonts /storage/logs /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c7d264b917d264b91fec2d378b737fa915c2fbb6d475a753c
Found 52 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/database/factories /source/database/migrations /source/database/seeders /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /themes
Severity: low
Fingerprint: 5f32cf5d6962f09c81c345f781c345f72d6a92f628e0edb729ee3887261f859a
Found 32 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c2acf29aa2acf29aade216b490fa4de94758303889cc81ea6
Found 33 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09ccbc000d9cbc000d9ec12ee501ca04419572a77e53745ccff
Found 49 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /themes
Severity: low
Fingerprint: 5f32cf5d6962f09c87f05b7087f05b7054129fef51357d329c806e6a0ae6616e
Found 26 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
Severity: low
Fingerprint: 5f32cf5d6962f09cab28146bab28146bedb23fa2e4f419b39860230b14882453
Found 21 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Domains /app/Domains/Web /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c910c508a910c508a9652db29995f71f4d2b941683a4f5394
Found 55 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/database/factories /source/database/migrations /source/database/seeders /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /storage/app /storage/fonts /storage/logs /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c7d264b917d264b91fec2d378b737fa915c2fbb6d475a753c
Found 52 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/database/factories /source/database/migrations /source/database/seeders /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09ccbc000d9cbc000d9ec12ee501ca04419572a77e53745ccff
Found 49 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /source/artisan /source/bootstrap /source/composer.json /source/composer.lock /source/config /source/database /source/package.json /source/phpunit.xml /source/public /source/README.md /source/resources /source/routes /source/server.php /source/tests /source/vendor /source/webpack.mix.js /storage /themes
Severity: medium
Fingerprint: 5f32cf5d6962f09c2acf29aa2acf29aade216b490fa4de94758303889cc81ea6
Found 33 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/Traits/WithMetadata.php /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
Severity: low
Fingerprint: 5f32cf5d6962f09c81c345f781c345f72d6a92f628e0edb729ee3887261f859a
Found 32 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Models/Merchant.php /app/Models/Traits /app/Models/User.php /app/Models/UserProfile.php /app/Models/UserSite.php /app/Models/UserSiteContent.php /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
Severity: low
Fingerprint: 5f32cf5d6962f09c87f05b7087f05b7054129fef51357d329c806e6a0ae6616e
Found 26 files trough .DS_Store spidering: /.gitignore /.htaccess /app /app/Console /app/Console/Commands /app/Console/Kernel.php /app/Domains /app/Domains/Web /app/Domains/Web/Controllers /app/Domains/Web/Middleware /app/Domains/Web/routes.php /app/Exceptions /app/helpers.php /app/Http /app/Models /app/Providers /app/Services /artisan /data-info.php /favicon.ico /index.php /notes.txt /QODE-EC2.pem /source /storage /themes
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a2a389cf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://hoiyen@bitbucket.org/iats/qcard-web.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a2a389cf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://hoiyen@bitbucket.org/iats/qcard-web.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master