.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c9e04c3bc9e04c3bca7f850319cd7993cd812edcece580857
Found 22 files trough .DS_Store spidering: /.git /888 /check.html /event /event/active /event/css /event/favicon.ico /event/img /event/index.html /event/js /event/mp4 /index.html /m /qphtml /qphtml/index.html /qphtml/static /README.md /robots.txt /static /static-betnew /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09cccdd54a0ccdd54a0904d808d3a77cc405b16a1eabb7cd4c8
Found 13 files trough .DS_Store spidering: /.git /888 /check.html /event /index.html /m /qphtml /README.md /robots.txt /static /static-betnew /ts-download /tsnew-download
Severity: low
Fingerprint: 5f32cf5d6962f09c81c345f781c345f7610898f0fc94e7ed2eb3313d062865f6
Found 32 files trough .DS_Store spidering: /.git /888 /check.html /event /event/active /event/css /event/favicon.ico /event/img /event/index.html /event/js /event/mp4 /index.html /m /qphtml /qphtml/index.html /qphtml/static /README.md /robots.txt /static /static-betnew /ts-download /ts-download/.vscode /ts-download/css /ts-download/images /ts-download/js /ts-download/muse-ui /tsnew-download /tsnew-download/.vscode /tsnew-download/css /tsnew-download/images /tsnew-download/js /tsnew-download/muse-ui
Severity: low
Fingerprint: 5f32cf5d6962f09c3838040e3838040e7ad6bcebe57a3e4283850fd4cb7266bc
Found 20 files trough .DS_Store spidering: /.git /888 /check.html /event /event/active /event/css /event/favicon.ico /event/img /event/index.html /event/js /event/mp4 /index.html /m /qphtml /README.md /robots.txt /static /static-betnew /ts-download /tsnew-download
The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65223e9c6927
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = root@6669786.com:lottery-site/lottery-repo-betnew fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master