WebRuns locallyNo account
Exposed .git directory dumper
Reconstruct a repository from an exposed .git directory - recovering source, deleted files, and secrets from the commit history.
Open in ctfpalDeploying by git clone and forgetting to block .git/ leaves the entire repository readable over HTTP. That is not just the current source - it is every version of every file, including the commit where someone added a password and the commit where they removed it.
Reconstructing it
.git/HEAD- confirms the directory is exposed and names the current branch. This is the one-request test..git/config- remote URLs, sometimes with credentials embedded..git/index- lists every tracked file, so you know what to fetch rather than guessing..git/objects/xx/yyyy...- the content itself, zlib-compressed and addressed by SHA-1..git/logs/HEAD- the reflog, which reaches commits no branch points at any more.
The same reasoning applies to .svn/, .hg/, and to .DS_Store, which lists directory contents and is often the fastest way to learn filenames that no wordlist would guess.