gitjacker v0.1 releases: Leak git repositories from misconfigured websites
gitjacker
Gitjacker downloads git repositories and extracts their contents from sites where the .git directory has been mistakenly uploaded. It will still manage to recover a significant portion of a repository even where directory listings are disabled.
For educational/penetration testing use only.
Changelog v0.1
- Fixed traversal issue
Installation
curl -s “https://raw.githubusercontent.com/liamg/gitjacker/master/scripts/install.sh” | bash
or grab a precompiled binary.
You will need to have git installed to use Gitjacker.
Use
Usage:
gitjacker [url] [flags]Flags:
-h, –help help for gitjacker
-o, –output-dir string Directory to output retrieved git repository – defaults to a temporary directory
-v, –verbose Enable verbose logging
Demo
Source: https://github.com/liamg/