The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f2656175
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://git.sr.ht/~macintoshpie/thing-y.com fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Open service 46.23.81.157:443 ยท thing-y.com
2026-01-23 01:42
HTTP/1.1 200 OK Access-Control-Allow-Origin: * Access-Control-Request-Methods: GET, HEAD, OPTIONS Content-Length: 56 Content-Security-Policy: default-src 'self' data: blob:; script-src 'self' 'unsafe-eval' 'unsafe-inline'; style-src 'self' 'unsafe-inline'; worker-src 'self' 'unsafe-eval' 'unsafe-inline' data: blob:; frame-src https:; img-src data: https:; media-src https:; object-src 'none'; sandbox allow-downloads allow-forms allow-modals allow-pointer-lock allow-popups allow-presentation allow-same-origin allow-scripts; Content-Type: text/html; charset=utf-8 Last-Modified: Wed, 05 Mar 2025 03:15:23 GMT Vary: Accept-Encoding Date: Fri, 23 Jan 2026 01:42:26 GMT Connection: close <body> <img width="100%" src="thing-y.jpeg"/> </body>