ENNAENNA

git-dumper vs SecretFinder

GitHub Stats

2.5k
Stars
2.4k
296
Forks
430
10
Issues
46
1mo ago
Updated
1y ago
MIT
License
GPL-3.0
Python
Language
Python

About git-dumper

git-dumper downloads and reconstructs Git repositories from web servers where the .git directory is accidentally exposed. Many deployments leave .git accessible, exposing full source code, commit history, configuration files, and potentially credentials. git-dumper handles the complex process of downloading individual Git objects, reconstructing the pack files, and rebuilding a complete working repository. It supports recursive object resolution, handles missing objects gracefully, and works through redirects and basic authentication. A critical tool for web application pentesting where source code access dramatically accelerates vulnerability discovery.

About SecretFinder

SecretFinder is a Python-based tool designed to uncover sensitive data such as API keys, tokens, and credentials within JavaScript files. By scanning JavaScript code, it identifies potentially exposed secrets that could lead to security breaches. Security testers and developers use SecretFinder to ensure that sensitive information is not inadvertently exposed in client-side scripts.

Platform Support

๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows
๐Ÿงlinux๐ŸŽmacos๐ŸชŸwindows

Tags

git-dumper only

git-exposuresource-codeweb-exploitationinformation-disclosurerecon

SecretFinder only

secretsapi-keysjavascriptcredentials