Skip to content

Git Mailmap File Disclosure

ID: git-mailmap

Severity: low

Author: geeknik,DhiyaneshDK

Tags: config,exposure,git,mailmap,files

Git Mailmap file is exposed.

id: git-mailmap
info:
name: Git Mailmap File Disclosure
author: geeknik,DhiyaneshDK
severity: low
description: Git Mailmap file is exposed.
reference: https://man7.org/linux/man-pages/man5/gitmailmap.5.html
classification:
cpe: cpe:2.3:a:git-scm:git:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 1
vendor: git-scm
product: git
shodan-query: html:mailmap
tags: config,exposure,git,mailmap,files
http:
- method: GET
path:
- "{{BaseURL}}/.mailmap"
matchers-condition: and
matchers:
- type: regex
regex:
- "(?:[a-z0-9!#$%&'*+/=?^_`{|}~-]+(?:\\.[a-z0-9!#$%&'*+/=?^_`{|}~-]+)*|\"(?:[\\x01-\\x08\\x0b\\x0c\\x0e-\\x1f\\x21\\x23-\\x5b\\x5d-\\x7f]|\\\\[\\x01-\\x09\\x0b\\x0c\\x0e-\\x7f])*\")@(?:(?:[a-z0-9](?:[a-z0-9-]*[a-z0-9])?\\.)+[a-z0-9](?:[a-z0-9-]*[a-z0-9])?|\\[(?:(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?)\\.){3}(?:25[0-5]|2[0-4][0-9]|[01]?[0-9][0-9]?|[a-z0-9-]*[a-z0-9]:(?:[\\x01-\\x08\\x0b\\x0c\\x0e-\\x1f\\x21-\\x5a\\x53-\\x7f]|\\\\[\\x01-\\x09\\x0b\\x0c\\x0e-\\x7f])+)\\])"
- type: word
part: header
words:
- "application/octet-stream"
- type: word
part: body
words:
- "# Theresa O'Connor:"
negative: true
- type: status
status:
- 200
# digest: 4b0a00483046022100eecca016a673aeef9fbf2f07525616616e84361c94f458265379c3c51efc097c022100cf5e6c0be01704fdd67f98d5d0cfea32f500b953f9a310d76c54840a1a1f5ebc:922c64590222798bb761d5b6d8e72950

This template is used to detect vulnerabilities in web applications. It can be used with the Nuclei tool to scan for specific patterns or behaviors.

Terminal window
$ nuclei -u "URL" -t "http/exposures/files/git-mailmap.yaml"

View on Github