
عدة هجوم لإدارة الكود المصدري
Source Code Management Attack Toolkit - SCMKit هي مجموعة أدوات يمكن استخدامها لمهاجمة أنظمة SCM. تتيح SCMKit للمستخدم تحديد نظام SCM ووحدة الهجوم لاستخدامها، إلى جانب تحديد بيانات اعتماد صالحة (اسم المستخدم/كلمة المرور أو مفتاح API) لنظام SCM المعني. حاليًا، أنظمة SCM التي تدعمها SCMKit هي GitHub Enterprise وGitLab Enterprise وBitbucket Server. تتضمن وحدات الهجوم المدعومة الاستطلاع وتصعيد الامتيازات والثبات. تم بناء SCMKit بطريقة نمطية، بحيث يمكن إضافة وحدات وأنظمة SCM جديدة في المستقبل من قبل مجتمع أمن المعلومات.
المكتبات الخارجية التالية مستخدمة في هذا المشروع.
| المكتبة | الرابط | الترخيص |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
اتبع الخطوات التالية لإعداد Visual Studio لترجمة المشروع بنفسك. يتطلب هذا مكتبة .NET يمكن تثبيتها من مدير حزم NuGet.
https://api.nuget.org/v3/index.jsonInstall-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Jsonالجدول التالي يوضح أماكن دعم كل وحدة
| سيناريو الهجوم | الوحدة | يتطلب مسؤول؟ | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| استطلاع | listrepo | لا | X | X | X |
| استطلاع | searchrepo | لا | X | X | X |
| استطلاع | searchcode | لا | X | X | X |
| استطلاع | searchfile | لا | X | X | X |
| استطلاع | listsnippet | لا | X | ||
| استطلاع | listrunner | لا | X | ||
| استطلاع | listgist | لا | X | ||
| استطلاع | listorg | لا | X | ||
| استطلاع | privs | لا | X | X | |
| استطلاع | protection | لا | X | ||
| ثبات | listsshkey | لا | X | X | X |
| ثبات | removesshkey | لا | X | X | X |
| ثبات | createsshkey | لا | X | X | X |
| ثبات | listpat | لا | X | X | |
| ثبات | removepat | لا | X | X | |
| ثبات | createpat | نعم (لـ GitLab Enterprise فقط) | X | X | |
| تصعيد الامتيازات | addadmin | نعم | X | X | X |
| تصعيد الامتيازات | removeadmin | نعم | X | X | X |
| استطلاع | adminstats | نعم | X |
اكتشاف المستودعات المستخدمة في نظام SCM معين
قم بتوفير وحدة listrepo، إلى جانب أي معلومات مصادقة ذات صلة والرابط. سيؤدي ذلك إلى إخراج اسم المستودع والرابط.
سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
سيؤدي هذا إلى سرد جميع المستودعات التي يمكن للمستخدم رؤيتها.
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local