Git stores a repository as a content-addressed object database under .git/: commits, trees, and blobs keyed by SHA-1, plus refs, a packed-object store, and a config. Everything an attacker wants follows from that layout. If a web server serves .git/, the whole tree and its history can be rebuilt offline. If history holds a credential that was later deleted, it is still in the object store. If a repository server is anonymous, it can be cloned. And because Git runs hooks and honors repository config automatically, a clone or a push can become code execution.
Triage#
curl -s -o /dev/null -w '%{http_code}\n' https://<target>/.git/HEAD # 200 + "ref: refs/heads/..." => exposed
nmap -p9418 -sV <target> # git:// daemon
git ls-remote git://<target>/<repo> # anonymous clone test
Pages#
- Exposed .git directory: rebuild the full source tree and config from a web-served
.git. - Secrets in history: recover credentials from commit history, dangling objects, and the reflog.
- Daemon: clone private repositories from an unauthenticated
git://service. - Hooks and config execution: code execution through hooks and clone-time configuration.