Ross ROSS = Recommend OSS · open-source software intelligence for agents

lijiejie/ds_store_exp

A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively. observed · 2026-08-28

github.com/lijiejie/ds_store_exp · Python observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3508
  • days_rel: n/a
  • days_push: 1215
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1736 stars · 293 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Python CLI exploit tool that parses exposed .DS_Store files on web servers to enumerate hidden files and directories, then recursively downloads them. It is used in penetration testing to discover sensitive files leaked by macOS Finder artifacts.

Use cases

  • find hidden files leaked via .DS_Store on a website
  • enumerate a web server's directory structure during a pentest
  • recursively download files exposed by a .DS_Store file
  • audit my own site for .DS_Store information disclosure
  • extract directory listings from macOS metadata files on a server

When to choose

  • you need to test or exploit .DS_Store file disclosure on a web server
  • you want a quick Python script to map and mirror exposed directories
  • you are doing a security assessment of a macOS-developed website

When to avoid

  • you need a full-featured web vulnerability scanner rather than a single-issue exploit
  • the target does not serve .DS_Store files
  • you need a maintained tool with a license or ongoing support

Facets

cli-tool · maturity maintenance

web-scraping security parser cli security penetration-testing developer-tools python cli cross-platform ds-store directory-listing exploit information-disclosure pentest

1 source

Member repositories

RepositoryRoleHealth v2
lijiejie/ds_store_expmain32

For agents

markdown · JSON · MCP: product_card(name="lijiejie/ds_store_exp")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem