Subversion keeps a working copy's metadata in a .svn directory. Since version 1.7 that is a single SQLite database (.svn/wc.db) plus a pristine store of the unmodified file content, while older layouts scattered a .svn folder with entries and text-base copies into every directory. Either way, a .svn directory that a web server serves gives up the full source and its metadata, and the repository server behind it often allows anonymous history access that recovers deleted files and committed credentials.
Triage#
curl -s -o /dev/null -w '%{http_code}\n' https://<target>/.svn/wc.db # 200 => exposed (>=1.7)
curl -s -o /dev/null -w '%{http_code}\n' https://<target>/.svn/entries # 200 => exposed (legacy)
nmap -p3690 -sV <target>; svn ls svn://<target>/ 2>/dev/null # svnserve, anonymous read
Pages#
- Exposed .svn directory: rebuild source and metadata from a web-served working copy.
- Repository history and credentials: reach Subversion history to recover removed files and credentials.