The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522bb3cbf20
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true ignorecase = true precomposeunicode = true [remote "origin"] url = git@gitlab.com:stutern/stutern-static.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master [pull] ff = only rebase = true [branch "tuition"] remote = origin merge = refs/heads/tuition
Severity: medium
Fingerprint: 2580fa947e78dd08e645819d1cc87ef2dbe095674f05709bd010d1d10503cb05
HTTP/1.1 200 OK
Date: Sat, 06 May 2023 05:09:33 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
x-amz-id-2: sIgwLrWrl1njQ282CN2jnB3dn8zD/eELvYFXL3Ad0YzzJ+xjJY8NfJOx+38G9icSh0Mzz53HCe8=
x-amz-request-id: D7YGFM61P7SKA4JV
Last-Modified: Sun, 30 Apr 2023 20:18:13 GMT
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=HCS5LdxXgiUeuydAy1kkhQQSrYQ68Uyx94BL8TKsb5Zht2ru3PeLGe3cb5NmF9NBaeyEdP4hbCfptbkeVjr7Pghz0yl7iIFdFY3atExPoWnCsefVKmPArV0Mri0%2FWA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7c2eb63538ac03f0-FRA
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
Page title: Learn Web Dev, UI/UX, Data Science & Get Hired | Stutern[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
ignorecase = true
precomposeunicode = true
[remote "origin"]
url = git@gitlab.com:stutern/stutern-static.git
fetch = +refs/heads/*:refs/remotes/origin/*
[branch "master"]
remote = origin
merge = refs/heads/master
[pull]
ff = only
rebase = true
[branch "tuition"]
remote = origin
merge = refs/heads/tuition
Severity: medium
Fingerprint: 2580fa947e78dd08e645819d1cc87ef2dbe095674f05709bd010d1d14f04f582
HTTP/1.1 200 OK
Date: Sat, 06 May 2023 05:09:33 GMT
Content-Type: text/html
Transfer-Encoding: chunked
Connection: close
x-amz-id-2: 2d/Gf7C2K22fHbuPMaS17K8ouf+GZ1IQLWMGoPJNZjfHbqFvJAWr/IU3czHlyKKBoqh80OFQaik=
x-amz-request-id: D7YKAKK0R29FCJME
Last-Modified: Sun, 30 Apr 2023 20:18:13 GMT
CF-Cache-Status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v3?s=OJRemn6pj3%2FPoTyavgegNTPUc35OPPISBoL9hEClx3F1UkX0dOVO9DN8MVFG4sj13ge61GpREqjVxQzePfwDIL%2FZTDxfLy5%2BwfMH28ChT18UnAjG7n6Z4VeCmlrXXA%3D%3D"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
CF-RAY: 7c2eb6335f402c65-FRA
alt-svc: h3=":443"; ma=86400, h3-29=":443"; ma=86400
Page title: Learn Web Dev, UI/UX, Data Science & Get Hired | Stutern[core]
repositoryformatversion = 0
filemode = true
bare = false
logallrefupdates = true
ignorecase = true
precomposeunicode = true
[remote "origin"]
url = git@gitlab.com:stutern/stutern-static.git
fetch = +refs/heads/*:refs/remotes/origin/*
[branch "master"]
remote = origin
merge = refs/heads/master
[pull]
ff = only
rebase = true
[branch "tuition"]
remote = origin
merge = refs/heads/tuition
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09c3e8b9cac3e8b9cac0b6b4661f8e16fa3d142c96a01b68f8a
Found 48 files trough .DS_Store spidering: /.git /.idea /.jekyll-cache /404.html /about.html /accelerator /accelerator.html /android-chrome-192x192.png /android-chrome-512x512.png /apple-touch-icon.png /apply /apply/beginners-course /apply/intermediate-course /beginners-course /contact.html /css /faq.html /favicon-16x16.png /favicon-32x32.png /favicon.ico /fonts /fonts/Silka /frankdonga.png /Gemfile /Gemfile.lock /images /images/accelerator /images/beginners-course /images/companies /images/foundation /images/logo /images/opengraph-twitter.jpg /images/opengraph.jpg /images/others /images/people /images/research /index.html /intermediate-course /javascript /package-lock.json /README.md /research /research.html /robots.txt /scholarships.html /short-courses.html /sitemap.xml /terms_and_policy.html
Severity: medium
Fingerprint: 5f32cf5d6962f09c8f03d7bd8f03d7bd6e3758f6bcefcc882f99d1cd33c17c79
Found 38 files trough .DS_Store spidering: /.git /.idea /.jekyll-cache /404.html /about.html /accelerator /accelerator.html /android-chrome-192x192.png /android-chrome-512x512.png /apple-touch-icon.png /apply /apply/beginners-course /apply/intermediate-course /beginners-course /contact.html /css /faq.html /favicon-16x16.png /favicon-32x32.png /favicon.ico /fonts /fonts/Silka /frankdonga.png /Gemfile /Gemfile.lock /images /index.html /intermediate-course /javascript /package-lock.json /README.md /research /research.html /robots.txt /scholarships.html /short-courses.html /sitemap.xml /terms_and_policy.html
Severity: medium
Fingerprint: 5f32cf5d6962f09c91500896915008961d7897132bf7fa5508c32d5c8dc1ffe2
Found 37 files trough .DS_Store spidering: /.git /.idea /.jekyll-cache /404.html /about.html /accelerator /accelerator.html /android-chrome-192x192.png /android-chrome-512x512.png /apple-touch-icon.png /apply /apply/beginners-course /apply/intermediate-course /beginners-course /contact.html /css /faq.html /favicon-16x16.png /favicon-32x32.png /favicon.ico /fonts /frankdonga.png /Gemfile /Gemfile.lock /images /index.html /intermediate-course /javascript /package-lock.json /README.md /research /research.html /robots.txt /scholarships.html /short-courses.html /sitemap.xml /terms_and_policy.html
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: medium
Fingerprint: 5f32cf5d6962f09cee671e0bee671e0bae4f515193e49d2671d0d46f03aac9b2
Found 72 files trough .DS_Store spidering: /_compatibility.php /_install.php /api /app.php /autoresponders-create.php /autoresponders-edit.php /autoresponders-emails.php /autoresponders-list.php /autoresponders-report.php /autoresponders.php /blacklist-blocked-domains.php /blacklist-suppression.php /campaigns-rss.php /certs /clear-queue.php /confirm.php /create-template.php /create.php /css /custom-fields.php /delete-from-list.php /detect-table-conflicts.php /edit-brand.php /edit-list.php /edit-template.php /edit.php /eula.txt /housekeeping-inactive.php /housekeeping-unconfirmed.php /img /import-csv.php /includes /index.php /js /l.php /list.php /locale /locale/en_US /login.php /logout.php /new-brand.php /new-list.php /payment.php /phpinfo.php /r.php /reconsent-success.php /remove-duplicates.php /report.php /reports.php /reset-cron.php /scheduled.php /search-all-brands.php /search-all-lists.php /segment.php /segments-list.php /send-to.php /sending.php /settings.php /subscribe.php /subscribers.php /subscription.php /t.php /template-preview.php /templates.php /two-factor.php /unsubscribe-from-list.php /unsubscribe-success.php /unsubscribe.php /update-list.php /update-segments.php /verification-status.php /w.php
Severity: medium
Fingerprint: 5f32cf5d6962f09c8ef2655c8ef2655c79b53a340d93306d347b70e8d7eca139
Found 71 files trough .DS_Store spidering: /_compatibility.php /_install.php /api /app.php /autoresponders-create.php /autoresponders-edit.php /autoresponders-emails.php /autoresponders-list.php /autoresponders-report.php /autoresponders.php /blacklist-blocked-domains.php /blacklist-suppression.php /campaigns-rss.php /certs /clear-queue.php /confirm.php /create-template.php /create.php /css /custom-fields.php /delete-from-list.php /detect-table-conflicts.php /edit-brand.php /edit-list.php /edit-template.php /edit.php /eula.txt /housekeeping-inactive.php /housekeeping-unconfirmed.php /img /import-csv.php /includes /index.php /js /l.php /list.php /locale /login.php /logout.php /new-brand.php /new-list.php /payment.php /phpinfo.php /r.php /reconsent-success.php /remove-duplicates.php /report.php /reports.php /reset-cron.php /scheduled.php /search-all-brands.php /search-all-lists.php /segment.php /segments-list.php /send-to.php /sending.php /settings.php /subscribe.php /subscribers.php /subscription.php /t.php /template-preview.php /templates.php /two-factor.php /unsubscribe-from-list.php /unsubscribe-success.php /unsubscribe.php /update-list.php /update-segments.php /verification-status.php /w.php