从配置不当的 Web 服务器转储 Git 数据
netspi.com | 博客 | #git | #pentesting | #web-security | #information-disclosure | #source-code-exposure | #wget
摘要
Web 服务器一旦公开暴露 .git 目录,就等于把完整仓库历史拱手送给攻击者。文章介绍如何发现暴露的仓库、用 wget 递归镜像下载,并从中还原源代码与 SMTP 凭据等配置信息。
- 发布时间
- 收录时间
Skip to content