The following URL (usually /.git/config
) is publicly accessible and is leaking source code and repository configuration.
Additionally the GIT credentials are present and could give unauthorized access to source code repository of private projects.
Severity: critical
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d0c1671f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://businesstodayDeveloper:B22760904t@bitbucket.org/businesstodayDeveloper/businesstoday.git fetch = +refs/heads/*:refs/remotes/origin/* [branch "master"] remote = origin merge = refs/heads/master
Open service 52.194.9.32:443 · c-b-un.com
2024-10-02 01:14
HTTP/1.1 404 Not Found Date: Wed, 02 Oct 2024 01:14:35 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 19 Connection: close X-Content-Type-Options: nosniff 404 page not found
Open service 52.194.9.32:443 · c-b-un.com
2024-09-30 01:21
HTTP/1.1 404 Not Found Date: Mon, 30 Sep 2024 01:21:24 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 19 Connection: close X-Content-Type-Options: nosniff 404 page not found
Open service 52.194.9.32:443 · c-b-un.com
2024-09-28 01:22
HTTP/1.1 404 Not Found Date: Sat, 28 Sep 2024 01:22:08 GMT Content-Type: text/plain; charset=utf-8 Content-Length: 19 Connection: close X-Content-Type-Options: nosniff 404 page not found