SVN

Subversion keeps a working copy's metadata in a .svn directory. Since version 1.7 that is a single SQLite database (.svn/wc.db) plus a pristine store of the unmodified file content, while older layouts scattered a .svn folder with entries and text-base copies into every directory. Either way, a .svn directory that a web server serves gives up the full source and its metadata, and the repository server behind it often allows anonymous history access that recovers deleted files and committed credentials.

Triage#

bash
curl -s -o /dev/null -w '%{http_code}\n' https://<target>/.svn/wc.db          # 200 => exposed (>=1.7)
curl -s -o /dev/null -w '%{http_code}\n' https://<target>/.svn/entries        # 200 => exposed (legacy)
nmap -p3690 -sV <target>; svn ls svn://<target>/ 2>/dev/null                  # svnserve, anonymous read

Pages#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more