mirror of
https://github.com/myronblair/orbis-hosting-portal
synced 2026-07-28 05:03:00 -05:00
Block public access to .git directory (leaked live GitHub PAT)
The docRoot is the git working tree, so .git/ was directly downloadable over HTTPS (curl https://orbis.orbishosting.com/.git/config returned 200), exposing the origin remote URL with an embedded GitHub personal access token in plaintext. Added a .htaccess denying dotfiles/.git and a matching OpenLiteSpeed vhost context as defense in depth. The exposed token should be revoked/rotated on GitHub regardless of this fix.
This commit is contained in:
@@ -0,0 +1,9 @@
|
|||||||
|
# Block direct web access to the .git directory and other dotfiles.
|
||||||
|
# The .git folder lives inside public_html (docRoot) and was found to be
|
||||||
|
# directly downloadable over HTTPS (e.g. https://orbis.orbishosting.com/.git/config),
|
||||||
|
# which leaked a live GitHub personal access token embedded in the remote URL.
|
||||||
|
RedirectMatch 404 /\.git
|
||||||
|
|
||||||
|
<FilesMatch "^\.">
|
||||||
|
Require all denied
|
||||||
|
</FilesMatch>
|
||||||
@@ -62,6 +62,11 @@ rewrite {
|
|||||||
autoLoadHtaccess 1
|
autoLoadHtaccess 1
|
||||||
}
|
}
|
||||||
|
|
||||||
|
context /.git {
|
||||||
|
location /dev/null
|
||||||
|
allowBrowse 0
|
||||||
|
}
|
||||||
|
|
||||||
context /.well-known/acme-challenge {
|
context /.well-known/acme-challenge {
|
||||||
location /usr/local/lsws/Example/html/.well-known/acme-challenge
|
location /usr/local/lsws/Example/html/.well-known/acme-challenge
|
||||||
allowBrowse 1
|
allowBrowse 1
|
||||||
|
|||||||
Reference in New Issue
Block a user