1/600 Websites have .git folder exposed – Check it immediately! – Unprotected .git folders can leak sensitive information.
Jamie Brown, developer and co-founder of the British-Chinese startup Chicmi, has published an interesting blog post in which he describes how respectable websites have the contents of their .git folder open.
If you're not familiar with Git, it's a technology developed by Linus Torvalds, the creator of Linux, and was created to track code changes and modifications to the Linux kernel.
The technology is already 10 years old and is widely adopted by Web, desktop, and mobile developers thanks to its ease of use and success on GitHub.
To help you track code changes, Git creates a hidden folder called “.git,” which can contain a wide range of information. It can include the basic code commits for the Git repo but also contain information stored within the repo, such as FTP credentials, API keys, database logins, and other sensitive information.
Developers who are aware of this detail usually protect their .git folder, which they never leave available online, but even if they do, they usually protect it from public access.
0.16% of the Internet has the .git folder listed
Mr. Brown's research into this topic reveals that, out of 1.5 million sites he scanned, 2,402 of them had their .git folder exposed. Some of these sites are quite reputable and reputable, including major news sites like the BBC, The Guardian, and various government and educational institution websites.
While some of the content found within them is harmless, some of it also includes some disturbing details.
If you work with Git, the first thing to check is if you are vulnerable to this issue, visit https://www.yourdomain.com/.git/
If your browser creates a list of the contents of your folder, then you will immediately need to create a .htaccess file inside it and prevent users from viewing it.
After making sure no one else can see it, you can browse its contents and see if sensitive data was exposed in the past.
If so, the most important step is to change all exposed credentials and you should do so immediately.

