Skip to content

Git for Hacking

Git is the version control almost everyone uses, and for a pentester it has two sides: it’s the tool you clone and manage your arsenal with (thousands of exploit and tool repos), and it’s a source of findings —exposed repos, committed secrets, and accessible .git/ directories on sites that leak their entire source code. Knowing Git is knowing how to recover what people thought they’d deleted.

git clone https://github.com/user/repo # download a repo (your arsenal)
git pull # update
git log --oneline # commit history
git diff # uncommitted changes
git show <commit> # view a specific commit
git branch -a ; git checkout <branch> # branches

The key concept: Git keeps the entire history. A deleted file or a secret “removed” in a later commit is still in the history and can be recovered.

If a web server serves the .git/ directory (careless deployment), you can reconstruct the full source code of the site, including secrets and logic:

# detect
curl -s https://target/.git/HEAD # if it returns "ref: refs/heads/..." -> exposed
# dump and reconstruct
git-dumper https://target/.git/ ./output

With the recovered code you hunt for credentials, hidden endpoints, keys, and logic vulnerabilities.

Developers commit keys by mistake and then “delete them” in another commit —but the history keeps them:

# search for secrets across a repo's whole history
trufflehog git https://github.com/org/repo
gitleaks detect --source .
git log -p | grep -iE 'password|api_key|secret|token'

In recon, a company’s (and its employees’) public repos are a goldmine of leaked credentials (see Code Repository OSINT).

git clone --depth 1 <repo> # fast clone without history (you just want the tool)
pip install -r requirements.txt # many Python tools ship deps
# contribute / save your changes
git add . ; git commit -m "msg" ; git push

Hygiene (so you don’t leak what you hunt in others)

Section titled “Hygiene (so you don’t leak what you hunt in others)”
.gitignore # never commit .env, keys, private wordlists
git secrets / pre-commit hooks # block secrets before the commit

Two fronts: defensive/OSINT, exposed .git/ and secrets in histories are real, frequent findings in bug bounty and pentest; operational, the whole offensive tooling ecosystem lives on GitHub and you need Git to use, adapt, and maintain it. Plus, understanding branches/commits lets you audit third-party code before running it.

  • I clone, update, and navigate repos (clone, pull, log, checkout)
  • I understand that history keeps “deleted” content
  • I detect an exposed .git/ and reconstruct it (git-dumper)
  • I search histories for secrets with trufflehog/gitleaks
  • I recover a file or secret from an old commit
  • I use .gitignore and hooks so I don’t leak my own secrets
  • I clone tools with —depth 1 and install their dependencies