Git for Hacking
Git is the version control almost everyone uses, and for a pentester it has two sides: it’s the tool you clone and manage your arsenal with (thousands of exploit and tool repos), and it’s a source of findings —exposed repos, committed secrets, and accessible .git/ directories on sites that leak their entire source code. Knowing Git is knowing how to recover what people thought they’d deleted.
Basics
Section titled “Basics”git clone https://github.com/user/repo # download a repo (your arsenal)git pull # updategit log --oneline # commit historygit diff # uncommitted changesgit show <commit> # view a specific commitgit branch -a ; git checkout <branch> # branchesThe key concept: Git keeps the entire history. A deleted file or a secret “removed” in a later commit is still in the history and can be recovered.
The finding: exposed .git/ on websites
Section titled “The finding: exposed .git/ on websites”If a web server serves the .git/ directory (careless deployment), you can reconstruct the full source code of the site, including secrets and logic:
# detectcurl -s https://target/.git/HEAD # if it returns "ref: refs/heads/..." -> exposed# dump and reconstructgit-dumper https://target/.git/ ./outputWith the recovered code you hunt for credentials, hidden endpoints, keys, and logic vulnerabilities.
The finding: secrets in the history
Section titled “The finding: secrets in the history”Developers commit keys by mistake and then “delete them” in another commit —but the history keeps them:
# search for secrets across a repo's whole historytrufflehog git https://github.com/org/repogitleaks detect --source .git log -p | grep -iE 'password|api_key|secret|token'In recon, a company’s (and its employees’) public repos are a goldmine of leaked credentials (see Code Repository OSINT).
Working with your own arsenal
Section titled “Working with your own arsenal”git clone --depth 1 <repo> # fast clone without history (you just want the tool)pip install -r requirements.txt # many Python tools ship deps# contribute / save your changesgit add . ; git commit -m "msg" ; git pushHygiene (so you don’t leak what you hunt in others)
Section titled “Hygiene (so you don’t leak what you hunt in others)”.gitignore # never commit .env, keys, private wordlistsgit secrets / pre-commit hooks # block secrets before the commitWhy it matters in security
Section titled “Why it matters in security”Two fronts: defensive/OSINT, exposed .git/ and secrets in histories are real, frequent findings in bug bounty and pentest; operational, the whole offensive tooling ecosystem lives on GitHub and you need Git to use, adapt, and maintain it. Plus, understanding branches/commits lets you audit third-party code before running it.
Mastery checklist
Section titled “Mastery checklist”- I clone, update, and navigate repos (clone, pull, log, checkout)
- I understand that history keeps “deleted” content
- I detect an exposed
.git/and reconstruct it (git-dumper) - I search histories for secrets with trufflehog/gitleaks
- I recover a file or secret from an old commit
- I use .gitignore and hooks so I don’t leak my own secrets
- I clone tools with —depth 1 and install their dependencies