Skip to content

Redteam Tip - Google dork for .git folder exposure

Google dork to identify the git

Santhosh Baswa

11 March 2017, 1 min read

As a part of OSINT/Recon activity to identify sensitive information for specific organisation/website most of the security engineers were using Google dorks. In this article we were identifying the vulnerable websites which exposes .git folders in their web servers.

Google Dork - .git folder exposure:
Google dork
Git folder google dork

Google Dork:

intext:"index of /.git" "parent directory"

Defend .git folder exposed Web servers:

<Directory ~ “\.git”>
Order deny,allow
Deny from all
</Directory>

Tools used:

Google

Written by

Santhosh Baswa

I hunt and defend organisations’ environments, and in my free time I write up what I learn here and give technical sessions in open security communities.

Get new articles by email

One email when something substantial goes up. No tracking pixels, and one click to unsubscribe.