
소스 코드 관리 공격 툴킷
소스 코드 관리 공격 툴킷 - SCMKit는 SCM 시스템을 공격하는 데 사용할 수 있는 툴킷입니다. SCMKit를 사용하면 사용자는 사용할 SCM 시스템과 공격 모듈을 지정하고, 해당 SCM 시스템에 대한 유효한 자격 증명(사용자 이름/비밀번호 또는 API 키)을 지정할 수 있습니다. 현재 SCMKit가 지원하는 SCM 시스템은 GitHub Enterprise, GitLab Enterprise 및 Bitbucket Server입니다. 지원되는 공격 모듈에는 정찰, 권한 상승 및 지속성이 포함됩니다. SCMKit는 모듈식 접근 방식으로 구축되어, 미래에 정보 보안 커뮤니티에서 새로운 모듈과 SCM 시스템을 추가할 수 있습니다.
이 프로젝트에서는 다음과 같은 타사 라이브러리가 사용됩니다.
| 라이브러리 | URL | 라이선스 |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
프로젝트를 직접 컴파일하려면 아래 단계에 따라 Visual Studio를 설정하세요. 이 작업은 NuGet 패키지 관리자에서 설치할 수 있는 .NET 라이브러리가 필요합니다.
https://api.nuget.org/v3/index.jsonInstall-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Json아래 표는 각 모듈이 지원되는 위치를 보여줍니다.
| Attack Scenario | Module | Requires Admin? | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| 정찰 | listrepo | 아니요 | X | X | X |
| 정찰 | searchrepo | 아니요 | X | X | X |
| 정찰 | searchcode | 아니요 | X | X | X |
| 정찰 | searchfile | 아니요 | X | X | X |
| 정찰 | listsnippet | 아니요 | X | ||
| 정찰 | listrunner | 아니요 | X | ||
| 정찰 | listgist | 아니요 | X | ||
| 정찰 | listorg | 아니요 | X | ||
| 정찰 | privs | 아니요 | X | X | |
| 정찰 | protection | 아니요 | X | ||
| 지속성 | listsshkey | 아니요 | X | X | X |
| 지속성 | removesshkey | 아니요 | X | X | X |
| 지속성 | createsshkey | 아니요 | X | X | X |
| 지속성 | listpat | 아니요 | X | X | |
| 지속성 | removepat | 아니요 | X | X | |
| 지속성 | createpat | 예 (GitLab Enterprise 전용) | X | X | |
| 권한 상승 | addadmin | 예 | X | X | X |
| 권한 상승 | removeadmin | 예 | X | X | X |
| 정찰 | adminstats | 예 | X |
특정 SCM 시스템에서 사용 중인 리포지토리 발견
listrepo 모듈을 관련 인증 정보 및 URL과 함께 제공하세요. 그러면 리포지토리 이름과 URL이 출력됩니다.
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local
Name | Visibility | URL
MaraudersMap | Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
testingStuff | Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
Spellbook | Internal | https://gitlab.hogwarts.local/hpotter/spellbook
findShortestPathToGryffindorSword | Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
charms | Public | https://gitlab.hogwarts.local/hgranger/charms
Secret-Spells | Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
Monitoring | Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### 저장소 검색
#### 사용 사례
> *특정 SCM 시스템에서 저장소 이름으로 저장소를 검색합니다*
#### 구문
`-o` 명령줄 스위치에 `searchrepo` 모듈과 검색 조건을 제공하고, 관련 인증 정보 및 URL을 함께 입력합니다. 그러면 일치하는 저장소 이름과 URL이 출력됩니다.
##### GitHub Enterprise
GitHub 저장소 검색은 "포함" 검색으로, 입력한 문자열이 저장소 이름에 포함된 저장소를 검색합니다.
`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`
`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`
##### GitLab Enterprise
GitLab 저장소 검색은 "포함" 검색으로, 입력한 문자열이 저장소 이름에 포함된 저장소를 검색합니다.
`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`