
Source Code Management Attack Toolkit - SCMKit は、SCMシステムを攻撃するために使用できるツールキットです。SCMKit では、使用するSCMシステムと攻撃モジュールを指定し、該当するSCMシステムへの有効な認証情報(ユーザー名/パスワードまたはAPIキー)を指定できます。現在、SCMKit がサポートしているSCMシステムは、GitHub Enterprise、GitLab Enterprise、Bitbucket Server です。サポートされている攻撃モジュールには、偵察、権限昇格、永続化が含まれます。SCMKit はモジュール式で構築されているため、今後情報セキュリティコミュニティによって新しいモジュールやSCMシステムを追加できます。
このプロジェクトでは以下のサードパーティライブラリを使用しています。
| ライブラリ | URL | ライセンス |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
以下の手順に従って Visual Studio をセットアップし、自分でプロジェクトをコンパイルしてください。これには、NuGet パッケージマネージャーからインストールできる .NET ライブラリが必要です。
https://api.nuget.org/v3/index.json を使用してパッケージソースを追加します。Install-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Json以下の表は、各モジュールがサポートされている場所を示しています。
| 攻撃シナリオ | モジュール | 管理者権限が必要? | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| 偵察 | listrepo | いいえ | X | X | X |
| 偵察 | searchrepo | いいえ | X | X | X |
| 偵察 | searchcode | いいえ | X | X | X |
| 偵察 | searchfile | いいえ | X | X | X |
| 偵察 | listsnippet | いいえ | X | ||
| 偵察 | listrunner | いいえ | X | ||
| 偵察 | listgist | いいえ | X | ||
| 偵察 | listorg | いいえ | X | ||
| 偵察 | privs | いいえ | X | X | |
| 偵察 | protection | いいえ | X | ||
| 永続化 | listsshkey | いいえ | X | X | X |
| 永続化 | removesshkey | いいえ | X | X | X |
| 永続化 | createsshkey | いいえ | X | X | X |
| 永続化 | listpat | いいえ | X | X | |
| 永続化 | removepat | いいえ | X | X | |
| 永続化 | createpat | はい (GitLab Enterprise のみ) | X | X | |
| 権限昇格 | addadmin | はい | X | X | X |
| 権限昇格 | removeadmin | はい | X | X | X |
| 偵察 | adminstats | はい | X |
特定のSCMシステムで使用されているリポジトリを発見する
listrepo モジュールを、関連する認証情報およびURLとともに指定します。これにより、リポジトリ名とURLが出力されます。
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
これにより、ユーザーが表示できるすべてのリポジトリが一覧表示されます。
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local
Name | Visibility | URL
MaraudersMap | Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
testingStuff | Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
Spellbook | Internal | https://gitlab.hogwarts.local/hpotter/spellbook
findShortestPathToGryffindorSword | Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
charms | Public | https://gitlab.hogwarts.local/hgranger/charms
Secret-Spells | Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
Monitoring | Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### リポジトリの検索
#### ユースケース
> *特定のSCMシステム内でリポジトリ名によりリポジトリを検索します*
#### 構文
`searchrepo` モジュールと検索条件を `-o` コマンドラインスイッチで指定し、関連する認証情報とURLを付加します。これにより、一致するリポジトリ名とURLが出力されます。
##### GitHub Enterprise
GitHubのリポジトリ検索は「contains」検索であり、入力した文字列がリポジトリ名に含まれるリポジトリを検索します。
`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`
`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`
##### GitLab Enterprise
GitLabのリポジトリ検索は「contains」検索であり、入力した文字列がリポジトリ名に含まれるリポジトリを検索します。
`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`
`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`
##### Bitbucket Server
Bitbucketのリポジトリ検索は「starts with」検索であり、入力した文字列で始まるリポジトリ名を持つリポジトリを検索します。