All fixes

Remove a public .DS_Store file

exposed-dsstore

A .DS_Store file lists every filename in the directory it came from, handing an attacker a map of paths you never linked to. Delete it.

Why this matters

A macOS metadata file is publicly accessible. It reveals directory structure, which gives attackers reconnaissance data but is not directly exploitable.

Nginx

  1. 1 Remove .DS_Store from your deployment and block access
nginx
location ~ /\.DS_Store {
    deny all;
    return 404;
}

Does your app still have this?

Scan your domain