10
Aug
During a recent pentest while utilizing Nikto, an open source web vulnerability scanner, we discovered that https://www.example.com/.git/config was a readable, accessible file. Using Git to push to production is a little old school now...