Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
SCMKit — أداة هجوم لإدارة شيفرات المصدر | Kitploit
أدوات/GitHubGitHub/h4wkst3r/scmkit
تصعيد الامتيازاتالاستطلاعآليات الاستمراريةاختبار الاختراقالفريق الأحمر
GitHubh4wkst3r/scmkit

SCMKit

أداة هجوم لإدارة شيفرات المصدر

عرض المستودع
229541منذ 3 سنواتتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

SCMKit

الوصف

Source Code Management Attack Toolkit - SCMKit هي مجموعة أدوات يمكن استخدامها لمهاجمة أنظمة إدارة الكود المصدري (SCM). تسمح SCMKit للمستخدم بتحديد نظام SCM ووحدة الهجوم المراد استخدامها، بالإضافة إلى تحديد بيانات اعتماد صالحة (اسم مستخدم/كلمة مرور أو مفتاح API) لنظام SCM المعني. حاليًا، أنظمة SCM التي تدعمها SCMKit هي GitHub Enterprise و GitLab Enterprise و Bitbucket Server. تتضمن وحدات الهجوم المدعومة الاستطلاع ورفع الامتيازات والثبات. تم بناء SCMKit بطريقة نمطية، بحيث يمكن إضافة وحدات وأنظمة SCM جديدة في المستقبل من قبل مجتمع أمن المعلومات.

الإصدار

  • يمكن العثور على الإصدار 1.2 من SCMKit في Releases

جدول المحتويات

  • SCMKit
  • جدول المحتويات
  • التثبيت/البناء
    • المكتبات المستخدمة
    • المجمّع مسبقًا
    • البناء بنفسك
  • الاستخدام
    • الوسائط/الخيارات
    • الأنظمة
    • الوحدات
    • جدول تفاصيل الوحدات
  • أمثلة
    • سرد المستودعات
    • البحث عن المستودعات
    • البحث في الكود
    • البحث في الملفات
    • سرد القصاصات
    • سرد العمال
    • سرد النقاط
    • سرد المنظمات
    • الحصول على صلاحيات مفتاح API
    • إضافة مسؤول
    • إزالة مسؤول
    • إنشاء رمز وصول
    • سرد رموز الوصول
    • إزالة رمز وصول
    • إنشاء مفتاح SSH
    • سرد مفاتيح SSH
    • إزالة مفتاح SSH
    • سرد إحصائيات المسؤول
    • سرد حماية الفرع
  • الكشف
  • المراجع

التثبيت/البناء

المكتبات المستخدمة

المكتبات الخارجية التالية تابعة لجهات ثالثة مستخدمة في هذا المشروع.

المجمّع مسبقًا

  • استخدم الثنائي المجمّع مسبقًا في Releases

البناء بنفسك

اتبع الخطوات أدناه لإعداد Visual Studio من أجل تجميع المشروع بنفسك. يتطلب هذا مكتبة .NET يمكن تثبيتها من مدير الحزم NuGet.

  • قم بتحميل مشروع Visual Studio واذهب إلى "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"
  • اذهب إلى "NuGet Package Manager" --> "Package Sources"
  • أضف مصدر حزمة باستخدام الرابط https://api.nuget.org/v3/index.json
  • قم بتثبيت حزم NuGet التالية
    • Install-Package Costura.Fody -Version 3.3.3
    • Install-Package Octokit
    • Install-Package GitLabApiClient
    • Install-Package Newtonsoft.Json
  • يمكنك الآن بناء المشروع بنفسك!

الاستخدام

الوسائط/الخيارات

  • -c, -credential - بيانات الاعتماد للمصادقة (اسم المستخدم:كلمة المرور أو مفتاح API)
  • -s, -system - النظام المراد مهاجمته (github,gitlab,bitbucket)
  • -u, -url - الرابط لـ GitHub Enterprise أو GitLab Enterprise أو Bitbucket Server
  • -m, -module - الوحدة المراد تشغيلها
  • -o, -option - الخيارات (عند الاقتضاء)

الأنظمة (-s, -system)

  • github: GitHub Enterprise
  • gitlab: GitLab Enterprise
  • bitbucket: Bitbucket Server

الوحدات (-m, -module)

  • listrepo: سرد جميع المستودعات التي يمكن للمستخدم الحالي رؤيتها
  • searchrepo: البحث عن مستودع معين
  • searchcode: البحث عن كود يحتوي على مصطلح بحث معين
  • searchfile: البحث عن اسم ملف يحتوي على مصطلح بحث معين
  • listsnippet: سرد جميع القصاصات للمستخدم الحالي
  • listrunner: سرد جميع عمال GitLab المتاحين للمستخدم الحالي
  • listgist: سرد جميع النقاط للمستخدم الحالي
  • listorg: سرد جميع المنظمات التي ينتمي إليها المستخدم الحالي
  • privs: الحصول على صلاحيات رمز API الحالي
  • addadmin: ترقية مستخدم معين إلى دور المسؤول
  • removeadmin: خفض رتبة مستخدم معين من دور المسؤول
  • createpat: إنشاء رمز وصول شخصي للمستخدم المستهدف
  • listpat: سرد رموز الوصول الشخصية لمستخدم مستهدف
  • removepat: إزالة رمز وصول شخصي لمستخدم مستهدف
  • createsshkey: إنشاء مفتاح SSH للمستخدم الحالي
  • listsshkey: سرد مفاتيح SSH للمستخدم الحالي
  • removesshkey: إزالة مفتاح SSH للمستخدم الحالي
  • adminstats: الحصول على إحصائيات المسؤول (المستخدمون، المستودعات، المنظمات، النقاط)
  • protection: الحصول على إعدادات حماية الفرع

جدول تفاصيل الوحدات

الجدول أدناه يوضح مكان دعم كل وحدة

أمثلة

سرد المستودعات

حالة الاستخدام

اكتشاف المستودعات المستخدمة في نظام SCM معين

الصياغة

قم بتوفير الوحدة listrepo، بالإضافة إلى أي معلومات مصادقة ذات صلة والرابط. سيؤدي هذا إلى إخراج اسم المستودع والرابط.

GitHub Enterprise

سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.

SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local

GitLab Enterprise

سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.

SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local

Bitbucket Server

سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.

SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local

SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local

مثال على الإخراج```

C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local

================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 8:30:47 PM

root@kitploit:~
                                Name | Visibility |                                                URL

root@kitploit:~
                        MaraudersMap |    Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
                        testingStuff |   Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
                           Spellbook |   Internal |    https://gitlab.hogwarts.local/hpotter/spellbook
   findShortestPathToGryffindorSword |   Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
                              charms |     Public |      https://gitlab.hogwarts.local/hgranger/charms
                       Secret-Spells |   Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
                          Monitoring |   Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
root@kitploit:~
### البحث عن المستودعات

#### حالة الاستخدام

> *البحث عن المستودعات حسب اسم المستودع في نظام إدارة الشيفرات المصدرية (SCM) معين*

#### الصيغة

قم بتوفير وحدة `searchrepo` ومعايير البحث الخاصة بك في مفتاح سطر الأوامر `-o`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج اسم المستودع المطابق وعنوان URL الخاص به.

##### GitHub Enterprise

بحث مستودعات GitHub هو بحث "يحتوي على" حيث السلسلة النصية التي تدخلها ستبحث عن المستودعات بأسماء تحتوي على مصطلح البحث الخاص بك.

`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`

`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`

##### GitLab Enterprise

بحث مستودعات GitLab هو بحث "يحتوي على" حيث السلسلة النصية التي تدخلها ستبحث عن المستودعات بأسماء تحتوي على مصطلح البحث الخاص بك.

`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`

`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`

##### Bitbucket Server

بحث مستودعات Bitbucket هو بحث "يبدأ بـ" حيث السلسلة النصية التي تدخلها ستبحث عن المستودعات بأسماء تبدأ بمصطلح البحث الخاص بك.

`SCMKit.exe -s bitbucket -m searchrepo -c userName:password -u https://bitbucket.something.local -o "some search term"`

`SCMKit.exe -s bitbucket -m searchrepo -c apikey -u https://bitbucket.something.local -o "some search term"`

#### مثال على المخرجات```

C:\>SCMKit.exe -s gitlab -m searchrepo -c apiKey -u https://gitlab.hogwarts.local -o "spell"

==================================================
Module:         searchrepo
System:         gitlab
Auth Type:      API Key
Options:        spell
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/14/2022 8:32:30 PM
==================================================

                                    Name | Visibility |                                                URL
----------------------------------------------------------------------------------------------------------
                               Spellbook |   Internal |    https://gitlab.hogwarts.local/hpotter/spellbook
                           Secret-Spells |   Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells

بحث الكود

حالة الاستخدام

البحث عن كود يحتوي على كلمة مفتاحية معينة في نظام إدارة المصدر (SCM) معين

الصيغة

قم بتوفير وحدة searchcode ومعايير البحث الخاصة بك في مفتاح سطر الأوامر -o، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيقوم هذا بإخراج عنوان URL لملف الكود المطابق، مع السطر في الكود الذي تطابق.

GitHub Enterprise

بحث كود GitHub هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن كود يحتوي على مصطلح البحث الخاص بك في أي سطر.

SCMKit.exe -s github -m searchcode -c userName:password -u https://github.something.local -o "some search term"

SCMKit.exe -s github -m searchcode -c apikey -u https://github.something.local -o "some search term"

GitLab Enterprise

بحث كود GitLab هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن كود يحتوي على مصطلح البحث الخاص بك في أي سطر.

SCMKit.exe -s gitlab -m searchcode -c userName:password -u https://gitlab.something.local -o "some search term"

SCMKit.exe -s gitlab -m searchcode -c apikey -u https://gitlab.something.local -o "some search term"

Bitbucket Server

بحث كود Bitbucket هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن كود يحتوي على مصطلح البحث الخاص بك في أي سطر.

SCMKit.exe -s bitbucket -m searchcode -c userName:password -u https://bitbucket.something.local -o "some search term"

SCMKit.exe -s bitbucket -m searchcode -c apikey -u https://bitbucket.something.local -o "some search term"

مثال على الإخراج```

C:>SCMKit.exe -s gitlab -m searchcode -c username:password -u https://gitlab.hogwarts.local -o "api_key"

================================================== Module: searchcode System: gitlab Auth Type: Username/Password Options: api_key Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 8:34:14 PM

[>] URL: https://gitlab.hogwarts.local/adumbledore/secret-spells/stuff.txt |_ API_KEY=abc123

Total number of items matching code search: 1

root@kitploit:~
### البحث عن الملفات

#### حالة الاستخدام

> *البحث عن الملفات في المستودعات التي تحتوي على كلمة مفتاحية معينة في اسم الملف في نظام إدارة المصادر (SCM) محدد*

#### الصيغة

قم بتوفير وحدة `searchfile` ومعايير البحث في الخيار `-o` في سطر الأوامر، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. سيؤدي ذلك إلى إخراج عنوان URL للملف المطابق في المستودع الخاص به.

##### GitHub Enterprise

بحث ملفات GitLab هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن الملفات التي تحتوي على مصطلح البحث الخاص بك في اسم الملف.

`SCMKit.exe -s github -m searchfile -c userName:password -u https://github.something.local -o "some search term"`

`SCMKit.exe -s github -m searchfile -c apikey -u https://github.something.local -o "some search term"`

##### GitLab Enterprise

بحث ملفات GitLab هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن الملفات التي تحتوي على مصطلح البحث الخاص بك في اسم الملف.

`SCMKit.exe -s gitlab -m searchfile -c userName:password -u https://gitlab.something.local -o "some search term"`

`SCMKit.exe -s gitlab -m searchfile -c apikey -u https://gitlab.something.local -o "some search term"`

##### Bitbucket Server

بحث ملفات Bitbucket هو بحث "يحتوي على" حيث السلسلة التي تدخلها ستبحث عن الملفات التي تحتوي على مصطلح البحث الخاص بك في اسم الملف.

`SCMKit.exe -s bitbucket -m searchfile -c userName:password -u https://bitbucket.something.local -o "some search term"`

`SCMKit.exe -s bitbucket -m searchfile -c apikey -u https://bitbucket.something.local -o "some search term"`

#### مثال للإخراج```

C:\source\SCMKit\SCMKit\bin\Release>SCMKit.exe -s bitbucket -m searchfile -c apikey -u http://bitbucket.hogwarts.local:7990 -o jenkinsfile

==================================================
Module:         searchfile
System:         bitbucket
Auth Type:      API Key
Options:        jenkinsfile
Target URL:     http://bitbucket.hogwarts.local:7990

Timestamp:      1/14/2022 10:17:59 PM
==================================================


[>] REPO: http://bitbucket.hogwarts.local:7990/scm/~HPOTTER/hpotter
    [>] FILE: Jenkinsfile

[>] REPO: http://bitbucket.hogwarts.local:7990/scm/STUD/cred-decryption
    [>] FILE: subDir/Jenkinsfile

Total matching results: 2

قائمة المقتطفات

حالة الاستخدام

سرد المقتطفات المملوكة للمستخدم الحالي في GitLab

الصيغة

قم بتوفير وحدة listsnippet، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL.

GitLab Enterprise

SCMKit.exe -s gitlab -m listsnippet -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listsnippet -c apikey -u https://gitlab.something.local

مثال الإخراج```

C:>SCMKit.exe -s gitlab -m listsnippet -c username:password -u https://gitlab.hogwarts.local

================================================== Module: listsnippet System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 9:17:36 PM

root@kitploit:~
           Title |                                                                Raw URL

root@kitploit:~
    spell-script |                         https://gitlab.hogwarts.local/-/snippets/2/raw
root@kitploit:~
### قائمة العمال

#### حالة الاستخدام

> *سرد جميع عمال GitLab المتاحة للمستخدم الحالي في GitLab*

#### الصيغة

قم بتوفير الوحدة `listrunner`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. إذا كان المستخدم مسؤولاً، فستتمكن من سرد جميع العمال داخل مثيل GitLab Enterprise، والذي يشمل العمال المشتركين والعمال الجماعيين.

##### GitLab Enterprise

`SCMKit.exe -s gitlab -m listrunner -c userName:password -u https://gitlab.something.local`

`SCMKit.exe -s gitlab -m listrunner -c apikey -u https://gitlab.something.local`

#### مثال على المخرجات```

C:\>SCMKit.exe -s gitlab -m listrunner -c username:password -u https://gitlab.hogwarts.local

==================================================
Module:         listrunner
System:         gitlab
Auth Type:      Username/Password
Options:
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/25/2022 11:40:08 AM
==================================================

   ID |                 Name |                                      Repo Assigned
---------------------------------------------------------------------------------
    2 |        gitlab-runner | https://gitlab.hogwarts.local/hpotter/spellbook.git
    3 |        gitlab-runner | https://gitlab.hogwarts.local/hpotter/maraudersmap.git
    

قائمة Gists

حالة الاستخدام

قائمة الجيستات المملوكة من قبل المستخدم الحالي في GitHub

الصيغة

قم بتوفير الوحدة النمطية listgist، إلى جانب أي معلومات توثيق وعنوان URL ذات صلة.

GitHub Enterprise

SCMKit.exe -s github -m listgist -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listgist -c apikey -u https://github.something.local

مثال على الإخراج```

C:>SCMKit.exe -s github -m listgist -c username:password -u https://github-enterprise.hogwarts.local

================================================== Module: listgist System: github Auth Type: Username/Password Options: Target URL: https://github-enterprise.hogwarts.local

Timestamp: 1/14/2022 9:43:23 PM

root@kitploit:~
                         Description | Visibility |                                                URL

root@kitploit:~
        Shell Script to Decode Spell |     public | https://github-enterprise.hogwarts.local/gist/c11c6bb3f47fe67183d5bc9f048412a1
        
root@kitploit:~
### قائمة المنظمات

#### حالة الاستخدام

> *سرد جميع المنظمات التي ينتمي إليها المستخدم الحالي في GitHub*

#### الصيغة

قم بتوفير الوحدة `listorg`، إلى جانب معلومات المصادقة ذات الصلة وعنوان URL.

##### GitHub Enterprise

`SCMKit.exe -s github -m listorg -c userName:password -u https://github.something.local`

`SCMKit.exe -s github -m listorg -c apiKey -u https://github.something.local`

#### مثال على الإخراج```

C:\>SCMKit.exe -s github -m listorg -c username:password -u https://github-enterprise.hogwarts.local

==================================================
Module:         listorg
System:         github
Auth Type:      Username/Password
Options:
Target URL:     https://github-enterprise.hogwarts.local

Timestamp:      1/14/2022 9:44:48 PM
==================================================

                          Name |                                                URL
-----------------------------------------------------------------------------------
                      Hogwarts | https://github-enterprise.hogwarts.local/api/v3/orgs/Hogwarts/repos
                      

الحصول على صلاحيات رمز API

حالة الاستخدام

الحصول على الصلاحيات المخصصة لرمز الوصول المستخدم في نظام SCM معين

الصيغة

قم بتوفير وحدة privs، بالإضافة إلى مفتاح API وعنوان URL.

GitHub Enterprise

SCMKit.exe -s github -m privs -c apiKey -u https://github.something.local

GitLab Enterprise

SCMKit.exe -s gitlab -m privs -c apiKey -u https://gitlab.something.local

مثال للإخراج

root@kitploit:~

C:>SCMKit.exe -s gitlab -m privs -c apikey -u https://gitlab.hogwarts.local

================================================== Module: privs System: gitlab Auth Type: API Key Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 9:18:27 PM

root@kitploit:~
      Token Name |    Active? |            Privilege |                                                            Description

hgranger-api-token | True | api | Read-write for the complete API, including all groups and projects, the Container Registry, and the Package Registry. hgranger-api-token | True | read_user | Read-only for endpoints under /users. Essentially, access to any of the GET requests in the Users API. hgranger-api-token | True | read_api | Read-only for the complete API, including all groups and projects, the Container Registry, and the Package Registry. hgranger-api-token | True | read_repository | Read-only (pull) for the repository through git clone. hgranger-api-token | True | write_repository | Read-write (pull, push) for the repository through git clone. Required for accessing Git repositories over HTTP when 2FA is enabled.

root@kitploit:~
### إضافة مشرف

#### حالة الاستخدام

> *رفع مستخدم عادي إلى دور إداري في نظام SCM معين*

#### البنية

قم بتوفير وحدة `addadmin`، بالإضافة إلى أي معلومات مصادقة ذات صلة وURL. أيضًا، قدم المستخدم الهدف الذي ترغب في إضافة دور إداري له.

##### GitHub Enterprise

`SCMKit.exe -s github -m addadmin -c userName:password -u https://github.something.local -o targetUserName`

`SCMKit.exe -s github -m addadmin -c apikey -u https://github.something.local -o targetUserName`

##### GitLab Enterprise

`SCMKit.exe -s gitlab -m addadmin -c userName:password -u https://gitlab.something.local -o targetUserName`

`SCMKit.exe -s gitlab -m addadmin -c apikey -u https://gitlab.something.local -o targetUserName`

##### Bitbucket Server

فقط المصادقة باسم المستخدم وكلمة المرور مدعومة لتنفيذ إجراءات غير متعلقة بالمستودعات أو المشاريع في Bitbucket.

`SCMKit.exe -s bitbucket -m addadmin -c userName:password -u https://bitbucket.something.local -o targetUserName`

#### مثال على الإخراج```

C:\>SCMKit.exe -s gitlab -m addadmin -c apikey -u https://gitlab.hogwarts.local -o hgranger

==================================================
Module:         addadmin
System:         gitlab
Auth Type:      API Key
Options:        hgranger
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/14/2022 9:19:32 PM
==================================================


[+] SUCCESS: The hgranger user was successfully added to the admin role.

إزالة المسؤول

حالة الاستخدام

تخفيض صلاحية مستخدم مسؤول إلى دور مستخدم عادي في نظام إدارة المصادر (SCM) معين

الصيغة

قدم الوحدة removeadmin، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. كما قدم المستخدم الهدف الذي ترغب في إزالة الدور الإداري منه.

GitHub Enterprise

SCMKit.exe -s github -m removeadmin -c userName:password -u https://github.something.local -o targetUserName

SCMKit.exe -s github -m removeadmin -c apikey -u https://github.something.local -o targetUserName

GitLab Enterprise

SCMKit.exe -s gitlab -m removeadmin -c userName:password -u https://gitlab.something.local -o targetUserName

SCMKit.exe -s gitlab -m removeadmin -c apikey -u https://gitlab.something.local -o targetUserName

Bitbucket Server

يُدعم فقط مصادقة اسم المستخدم/كلمة المرور لتنفيذ الإجراءات غير المتعلقة بالمستودعات أو المشاريع في Bitbucket.

SCMKit.exe -s bitbucket -m removeadmin -c userName:password -u https://bitbucket.something.local -o targetUserName

مثال الإخراج```

C:>SCMKit.exe -s gitlab -m removeadmin -c username:password -u https://gitlab.hogwarts.local -o hgranger

================================================== Module: removeadmin System: gitlab Auth Type: Username/Password Options: hgranger Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 9:20:12 PM

[+] SUCCESS: The hgranger user was successfully removed from the admin role.

root@kitploit:~
### إنشاء رمز الوصول

#### حالة الاستخدام

> *إنشاء رمز وصول لاستخدامه في نظام SCM معين*

#### الصيغة

قم بتوفير وحدة `createpat`، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. بالإضافة إلى ذلك، قم بتوفير المستخدم المستهدف الذي ترغب في إنشاء رمز وصول له.

##### GitLab Enterprise

يمكن إجراء هذا فقط كمسؤول. ستقوم بتوفير اسم المستخدم الذي ترغب في إنشاء PAT له.

`SCMKit.exe -s gitlab -m createpat -c userName:password -u https://gitlab.something.local -o targetUserName`

`SCMKit.exe -s gitlab -m createpat -c apikey -u https://gitlab.something.local -o targetUserName`

##### Bitbucket Server

ينشئ PAT للمستخدم الحالي الذي يقوم بالمصادقة. في Bitbucket، لا يمكنك إنشاء PAT لمستخدم آخر، حتى كمسؤول. يتم دعم مصادقة اسم المستخدم/كلمة المرور فقط لتنفيذ إجراءات لا تتعلق بالمستودعات أو المشاريع في Bitbucket. قم بتدوين معرف PAT الذي يظهر بعد الإنشاء. ستحتاج إليه عندما تحتاج إلى إزالة PAT في المستقبل.

`SCMKit.exe -s bitbucket -m createpat -c userName:password -u https://bitbucket.something.local `

#### مثال على الإخراج```

C:\>SCMKit.exe -s gitlab -m createpat -c username:password -u https://gitlab.hogwarts.local -o hgranger

==================================================
Module:         createpat
System:         gitlab
Auth Type:      Username/Password
Options:        hgranger
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/20/2022 1:51:23 PM
==================================================

   ID |         Name |                          Token
-----------------------------------------------------
   59 | SCMKIT-AaCND |           R3ySx_8HUn6UQ_6onETx

[+] SUCCESS: The hgranger user personal access token was successfully added.


قائمة رموز الوصول

حالة الاستخدام

سرد رموز الوصول لمستخدم على نظام SCM معين

الصيغة

قم بتوفير الوحدة listpat، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL.

GitLab Enterprise

يتطلب صلاحيات المسؤول فقط إذا كنت تريد سرد رموز PAT لمستخدم آخر. يمكن للمستخدم العادي سرد رموز PAT الخاصة به.

SCMKit.exe -s gitlab -m listpat -c userName:password -u https://gitlab.something.local -o targetUser

SCMKit.exe -s gitlab -m listpat -c apikey -u https://gitlab.something.local -o targetUser

Bitbucket Server

سرد رموز الوصول للمستخدم الحالي. يتم دعم مصادقة اسم المستخدم/كلمة المرور فقط لتنفيذ إجراءات لا تتعلق بالمستودعات أو المشاريع في Bitbucket.

SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local

سرد رموز الوصول لمستخدم آخر (يتطلب صلاحيات المسؤول). يتم دعم مصادقة اسم المستخدم/كلمة المرور فقط لتنفيذ إجراءات لا تتعلق بالمستودعات أو المشاريع في Bitbucket.

SCMKit.exe -s bitbucket -m listpat -c userName:password -u https://bitbucket.something.local -o targetUser

مثال على الإخراج```

C:>SCMKit.exe -s gitlab -m listpat -c username:password -u https://gitlab.hogwarts.local -o hgranger

================================================== Module: listpat System: gitlab Auth Type: Username/Password Options: hgranger Target URL: https://gitlab.hogwarts.local

Timestamp: 1/20/2022 1:54:41 PM

ID | Name | Active? | Scopes

59 | SCMKIT-AaCND | True | api, read_repository, write_repository

root@kitploit:~
### إزالة رمز الوصول

#### حالة الاستخدام

> *إزالة رمز وصول لمستخدم في نظام SCM معين*

#### الصيغة

قم بتوفير الوحدة `removepat`، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL. بالإضافة إلى ذلك، قم بتوفير معرف PAT الخاص بالمستخدم المستهدف الذي ترغب في إزالة رمز الوصول له.

##### GitLab Enterprise

يتطلب مسؤولًا فقط إذا كنت تريد إزالة PAT لمستخدم آخر. يمكن للمستخدم العادي إزالة PAT الخاص به. يجب عليك تقديم معرف PAT المراد إزالته. يتم عرض هذا المعرف عند إنشاء PAT وأيضًا عند سرد PAT.

`SCMKit.exe -s gitlab -m removepat -c userName:password -u https://gitlab.something.local -o patID`

`SCMKit.exe -s gitlab -m removepat -c apikey -u https://gitlab.something.local -o patID`

##### Bitbucket Server

يتم دعم مصادقة اسم المستخدم/كلمة المرور فقط لتنفيذ الإجراءات غير المتعلقة بالمستودعات أو المشاريع في Bitbucket. يجب عليك تقديم معرف PAT المراد إزالته. يتم عرض هذا المعرف عند إنشاء PAT.

`SCMKit.exe -s bitbucket -m removepat -c userName:password -u https://bitbucket.something.local -o patID`

#### مثال على الإخراج

```text

C:>SCMKit.exe -s gitlab -m removepat -c apikey -u https://gitlab.hogwarts.local -o 58

================================================== Module: removepat System: gitlab Auth Type: API Key Options: 59 Target URL: https://gitlab.hogwarts.local

Timestamp: 1/20/2022 1:56:47 PM

[*] INFO: Revoking personal access token of ID: 59

[+] SUCCESS: The personal access token of ID 59 was successfully revoked.

root@kitploit:~
### إنشاء مفتاح SSH

#### حالة الاستخدام

> *إنشاء مفتاح SSH لاستخدامه في نظام SCM معين*

#### الصيغة

قم بتوفير الوحدة النمطية `createsshkey`، إلى جانب أي معلومات توثيق وعنوان URL ذي صلة.

##### GitHub Enterprise

ينشئ مفتاح SSH للمستخدم الحالي الذي يتم المصادقة باسمه.

`SCMKit.exe -s github -m createsshkey -c userName:password -u https://github.something.local -o "ssh public key"`

`SCMKit.exe -s github -m createsshkey -c apiToken -u https://github.something.local -o "ssh public key"`

##### GitLab Enterprise

ينشئ مفتاح SSH للمستخدم الحالي الذي يتم المصادقة باسمه. لاحظ معرف مفتاح SSH الذي يظهر بعد الإنشاء. ستحتاج إليه عندما تحتاج إلى إزالة مفتاح SSH في المستقبل.

`SCMKit.exe -s gitlab -m createsshkey -c userName:password -u https://gitlab.something.local -o "ssh public key"`

`SCMKit.exe -s gitlab -m createsshkey -c apiToken -u https://gitlab.something.local -o "ssh public key"`

##### Bitbucket Server

ينشئ مفتاح SSH للمستخدم الحالي الذي يتم المصادقة باسمه. يُدعم فقط توثيق اسم المستخدم/كلمة المرور لتنفيذ إجراءات غير متعلقة بالمستودعات أو المشاريع في Bitbucket. لاحظ معرف مفتاح SSH الذي يظهر بعد الإنشاء. ستحتاج إليه عندما تحتاج إلى إزالة مفتاح SSH في المستقبل.

`SCMKit.exe -s bitbucket -m createsshkey -c userName:password -u https://bitbucket.something.local -o "ssh public key"`

#### مثال على الإخراج```

C:\>SCMKit.exe -s bitbucket -m createsshkey -c username:password -u https://bitbucket.hogwarts.local -o "ssh-rsa..."

==================================================
Module:         createsshkey
System:         bitbucket
Auth Type:      Username/Password
Options:        ssh-rsa ...
Target URL:     http://bitbucket.hogwarts.local:7990

Timestamp:      2/7/2022 1:02:31 PM
==================================================

  SSH Key ID
------------
          16

[+] SUCCESS: The hpotter user SSH key was successfully added.


قائمة مفاتيح SSH

حالة الاستخدام

قم بإدراج مفاتيح SSH لمستخدم معين في نظام إدارة الكود المصدري (SCM) محدد

الصيغة

قم بتوفير الوحدة النمطية listsshkey، بالإضافة إلى أي معلومات مصادقة ذات صلة وعنوان URL.

GitHub Enterprise

قم بإدراج مفاتيح SSH للمستخدم الحالي. سيتضمن ذلك معرفات مفاتيح SSH، وهو أمر مطلوب عند الرغبة في إزالة مفتاح SSH.

SCMKit.exe -s github -m listsshkey -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listsshkey -c apiToken -u https://github.something.local

GitLab Enterprise

قم بإدراج مفاتيح SSH للمستخدم الحالي.

SCMKit.exe -s gitlab -m listsshkey -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listsshkey -c apiToken -u https://gitlab.something.local

Bitbucket Server

قم بإدراج مفاتيح SSH للمستخدم الحالي. يُدعم فقط مصادقة اسم المستخدم/كلمة المرور لتنفيذ الإجراءات غير المتعلقة بالمستودعات أو المشاريع في Bitbucket.

SCMKit.exe -s bitbucket -m listsshkey -c userName:password -u https://bitbucket.something.local

مثال على الإخراج```

C:>SCMKit.exe -s gitlab -m listsshkey -u http://gitlab.hogwarts.local -c apiToken

================================================== Module: listsshkey System: gitlab Auth Type: API Key Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 2/7/2022 4:09:40 PM

SSH Key ID | SSH Key Value | Title

root@kitploit:~
       9 | .....p50edigBAF4lipVZkAM= |         SCMKIT-RLzie
      10 | .....vGJLPGHiTwIxW9i+xAs= |         SCMKIT-muFGU
root@kitploit:~
### إزالة مفتاح SSH

#### حالة الاستخدام

> *إزالة مفتاح SSH لمستخدم في نظام إدارة المصادر (SCM) معين*

#### الصيغة

قم بتوفير الوحدة النمطية `removesshkey`، إلى جانب أي معلومات مصادقة ذات صلة وURL. بالإضافة إلى ذلك، قم بتوفير معرف مفتاح SSH للمستخدم المستهدف لإزالته.

##### GitHub Enterprise

يجب عليك توفير معرف مفتاح SSH لإزالته. يتم عرض هذا المعرف عند سرد مفاتيح SSH.

`SCMKit.exe -s github -m removesshkey -c userName:password -u https://github.something.local -o sshKeyID`

`SCMKit.exe -s github -m removesshkey -c apiToken -u https://github.something.local -o sshKeyID`

##### GitLab Enterprise

 يجب عليك توفير معرف مفتاح SSH لإزالته. يتم عرض هذا المعرف عند إنشاء مفتاح SSH ويتم عرضه أيضًا عند سرد مفاتيح SSH.

`SCMKit.exe -s gitlab -m removesshkey -c userName:password -u https://gitlab.something.local -o sshKeyID`

`SCMKit.exe -s gitlab -m removesshkey -c apiToken -u https://gitlab.something.local -o sshKeyID`

##### Bitbucket Server

يتم دعم المصادقة باسم المستخدم/كلمة المرور فقط لتنفيذ الإجراءات غير المتعلقة بالمستودعات أو المشاريع في Bitbucket. يجب عليك توفير معرف مفتاح SSH لإزالته. يتم عرض هذا المعرف عند إنشاء مفتاح SSH ويتم عرضه أيضًا عند سرد مفاتيح SSH.

`SCMKit.exe -s bitbucket -m removesshkey -c userName:password -u https://bitbucket.something.local -o sshKeyID`

#### مثال الإخراج```

C:\>SCMKit.exe -s bitbucket -m removesshkey -u http://bitbucket.hogwarts.local:7990 -c username:password -o 16

==================================================
Module:         removesshkey
System:         bitbucket
Auth Type:      Username/Password
Options:        16
Target URL:     http://bitbucket.hogwarts.local:7990

Timestamp:      2/7/2022 1:48:03 PM
==================================================


[+] SUCCESS: The SSH key of ID 16 was successfully revoked.

قائمة إحصائيات المشرف

حالة الاستخدام

عرض إحصائيات المشرف في GitHub Enterprise

الصيغة

قم بتوفير الوحدة النمطية adminstats، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. مطلوب صلاحية مشرف الموقع في GitHub Enterprise لاستخدام هذه الوحدة

GitHub Enterprise

SCMKit.exe -s github -m adminstats -c userName:password -u https://github.something.local

SCMKit.exe -s github -m adminstats -c apikey -u https://github.something.local

مثال على الإخراج```

C:>SCMKit.exe -s github -m adminstats -c username:password -u https://github-enterprise.hogwarts.local

================================================== Module: adminstats System: github Auth Type: Username/Password Options: Target URL: https://github-enterprise.hogwarts.local

Timestamp: 1/14/2022 9:45:50 PM

root@kitploit:~
 Admin Users |  Suspended Users |      Total Users

root@kitploit:~
           1 |                0 |                5


 Total Repos |      Total Wikis

root@kitploit:~
           4 |                0


  Total Orgs |   Total Team Members |      Total Teams

root@kitploit:~
           1 |                    0 |                0

Private Gists | Public Gists

root@kitploit:~
           0 |                1
           
root@kitploit:~
### قائمة حماية الفرع

#### حالة الاستخدام

> *قائمة حماية الفروع في GitHub Enterprise*

#### الصياغة

قم بتوفير وحدة `protection`، إلى جانب أي معلومات مصادقة ذات صلة وعنوان URL. اختياريًا، قم بتوفير سلسلة نصية في معلمة الخيارات لإرجاع النتائج المطابقة الموجودة في أسماء المستودعات.

##### GitHub Enterprise

`SCMKit.exe -s github -m protection -c userName:password -u https://github.something.local`

`SCMKit.exe -s github -m protection -c apikey -u https://github.something.local`

`SCMKit.exe -s github -m protection -c apikey -u https://github.something.local -o reponame`

#### مثال على الإخراج```
C:\>.\SCMKit.exe -u http://github.hogwarts.local -s github -c apiToken -m protection -o public-r

==================================================
Module:         protection
System:         github
Auth Type:      API Key
Options:        public-r
Target URL:     http://github.hogwarts.local

Timestamp:      8/29/2022 2:02:42 PM
==================================================

                     Repo |                    Branch |                                         Protection
----------------------------------------------------------------------------------------------------------
              public-repo |                       dev | Protected: True
                                                        Status checks must pass before merge:
                                                          Branch must be up-to-date before merge: True
                                                        Owner review required before merge: True
                                                        Approvals required before merge: 2
                                                        Protections apply to repo admins: True
              public-repo |                      main | Protected: False

الكشف

فيما يلي توقيعات ثابتة للاستخدام المحدد لهذه الأداة في حالتها الافتراضية:

  • معرف المشروع (Project GUID) - {266C644A-69B1-426B-A47C-1CF32B211F80}
    • انظر قاعدة Yara لـ SCMKit في هذا المستودع.
  • سلسلة وكيل المستخدم (User Agent String) - SCMKIT-5dc493ada400c79dd318abbe770dac7c
    • انظر قاعدة Snort لـ SCMKit في هذا المستودع.
  • أسماء رموز الوصول ومفاتيح SSH - رموز الوصول ومفاتيح SSH التي يتم إنشاؤها باستخدام الأداة تُسبق بالاسم SCMKIT-.

للحصول على إرشادات الكشف عن التقنيات المستخدمة من قبل الأداة، راجع منشور المدونة لـ X-Force Red.

المراجع

  • وثائق واجهة برمجة تطبيقات Bitbucket
    • https://developer.atlassian.com/server/bitbucket/reference/rest-api/
  • وثائق Octokit
    • https://octokitnet.readthedocs.io/en/latest/
    • https://github.com/octokit/octokit.net
  • وثائق واجهة برمجة تطبيقات GitHub
    • https://docs.github.com/en/rest/overview
  • وثائق واجهة برمجة تطبيقات GitLab
    • https://docs.gitlab.com/ee/api/api_resources.html
  • وثائق حزمة NuGet الخاصة بـ GitLabApiClient
    • https://github.com/nmklotas/GitLabApiClient
تنزيل الأداة
المكتبةالرابطالترخيص
Octokithttps://github.com/octokit/octokit.netMIT License
Fodyhttps://github.com/Fody/FodyMIT License
GitLabApiClienthttps://github.com/nmklotas/GitLabApiClientMIT License
Newtonsoft.Jsonhttps://github.com/JamesNK/Newtonsoft.JsonMIT License
سيناريو الهجومالوحدةيتطلب مسؤولًا؟GitHub EnterpriseGitLab EnterpriseBitbucket Server
استطلاعlistrepoلاXXX
استطلاعsearchrepoلاXXX
استطلاعsearchcodeلاXXX
استطلاعsearchfileلاXXX
استطلاعlistsnippetلاX
استطلاعlistrunnerلاX
استطلاعlistgistلاX
استطلاعlistorgلاX
استطلاعprivsلاXX
استطلاعprotectionلاX
ثباتlistsshkeyلاXXX
ثباتremovesshkeyلاXXX
ثباتcreatesshkeyلاXXX
ثباتlistpatلاXX
ثباتremovepatلاXX
ثباتcreatepatنعم (GitLab Enterprise فقط)XX
رفع امتيازاتaddadminنعمXXX
رفع امتيازاتremoveadminنعمXXX
استطلاعadminstatsنعمX