.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09cecc85b04ecc85b04ef23a1f91669c8ed684d3edb715a2188
Found 53 files trough .DS_Store spidering: /.git /about-us.html /assets /assets/css /assets/fonts /assets/images /assets/images/about-lady-phone.jpg /assets/images/app-store-grey.png /assets/images/app-store.png /assets/images/bg-patterns-half.png /assets/images/bg-patterns.png /assets/images/blog-header-img1.jpg /assets/images/blog-header-img2.jpg /assets/images/chevron-forward-circle-outline.png /assets/images/features /assets/images/footer-phone.png /assets/images/header-bg-a.jpg /assets/images/header-bg-b.jpg /assets/images/home-hero-phone.png /assets/images/info-img1.png /assets/images/info-img2.png /assets/images/info-img3.png /assets/images/info-img4.png /assets/images/join-team-img1.jpg /assets/images/join-team-img2.jpg /assets/images/light-bg-lg.png /assets/images/light-bg.png /assets/images/paul-osoghale.jpg /assets/images/play-store-grey.png /assets/images/play-store.png /assets/images/quote.png /assets/images/right-arrow.svg /assets/images/stash-icon-purple.png /assets/images/stash-logo.png /assets/images/team-pic.jpg /assets/images/testimonial-1.png /assets/images/testimonial-2.png /assets/images/testimonial-3.png /assets/js /blog-details.html /blog-list.html /blog-posts /contact-us.html /faq.html /feature-loan.html /feature-save.html /feature-spend.html /index.html /join-our-team.html /login.html /maintenance.html /privacy-policy.html /terms-and-conditions.html
Severity: low
Fingerprint: 5f32cf5d6962f09c668fcbec668fcbec813998a1937438c5e5bbf95337d32c3d
Found 17 files trough .DS_Store spidering: /.git /about-us.html /assets /blog-details.html /blog-list.html /blog-posts /contact-us.html /faq.html /feature-loan.html /feature-save.html /feature-spend.html /index.html /join-our-team.html /login.html /maintenance.html /privacy-policy.html /terms-and-conditions.html
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652282ef1a1a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = git@github.com:stashngr/website.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main