The Analyzer v1.0 — autonomous bug bounty engine with 20 attack vectors and Ollama brain
This commit is contained in:
40
vectors/17-git-exposure.sh
Executable file
40
vectors/17-git-exposure.sh
Executable file
@@ -0,0 +1,40 @@
|
||||
#!/usr/bin/env bash
|
||||
# Vector 17: .git Repository Exposure
|
||||
# Desc: Exposed .git directory leaking source code
|
||||
# Detect: Any web server
|
||||
# Severity: CRITICAL
|
||||
# Tools: curl, git
|
||||
|
||||
vector_gitex() {
|
||||
local target="$1"
|
||||
local report="$2"
|
||||
local findings=0
|
||||
local base=$(echo "$target" | sed 's|\(https\?://[^/]*\).*|\1|')
|
||||
|
||||
print_info "Checking .git exposure..."
|
||||
|
||||
local git_url="${base}/.git/HEAD"
|
||||
local response=$(curl -s --connect-timeout 5 --max-time 10 "$git_url" 2>/dev/null)
|
||||
|
||||
if echo "$response" | grep -qi "ref: refs/heads/\|refs/heads/master\|refs/heads/main"; then
|
||||
print_find ".git HEAD exposed!" "Full git repo may be downloadable at $base/.git/"
|
||||
|
||||
# Check more .git files
|
||||
local config=$(curl -s --connect-timeout 5 --max-time 10 "${base}/.git/config" 2>/dev/null)
|
||||
local objects_check=$(curl -s -o /dev/null -w "%{http_code}" --connect-timeout 5 --max-time 10 "${base}/.git/objects" 2>/dev/null)
|
||||
|
||||
echo "SEVERITY: CRITICAL
|
||||
VECTOR: .git Repository Exposure
|
||||
DETAIL: Complete .git directory exposed at ${base}/.git/
|
||||
EVIDENCE: .git/HEAD accessible with content: $response
|
||||
EXPLOIT: Use git-dumper: git-dumper $base/.git/ ./repo-out/
|
||||
Or: wget -r $base/.git/" > "$REPORTS_DIR/.finding_$(date +%s)_git-exposure.txt"
|
||||
findings=$((findings + 1))
|
||||
|
||||
print_info "Use: git-dumper $base/.git/ ./repo/"
|
||||
else
|
||||
print_skip "No .git exposure detected"
|
||||
fi
|
||||
|
||||
return $findings
|
||||
}
|
||||
Reference in New Issue
Block a user