Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SCMKit — 소스 코드 관리 공격 툴킷 | Kitploit
도구/GitHubGitHub/xforcered/scmkit
Privilege EscalationReconnaissancePersistence MechanismsInformation GatheringPost-ExploitationPenetration TestingRed Teaming
GitHubxforcered/scmkit

SCMKit

소스 코드 관리 공격 툴킷

저장소 보기
13419184년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SCMKit

설명

Source Code Management Attack Toolkit - SCMKit은 SCM 시스템을 공격하는 데 사용할 수 있는 툴킷입니다. SCMKit을 사용하면 SCM 시스템과 사용할 공격 모듈을 지정하고, 해당 SCM 시스템에 대한 유효한 자격 증명(사용자 이름/비밀번호 또는 API 키)을 지정할 수 있습니다. 현재 SCMKit이 지원하는 SCM 시스템은 GitHub Enterprise, GitLab Enterprise 및 Bitbucket Server입니다. 지원되는 공격 모듈에는 정찰, 권한 상승 및 지속이 포함됩니다. SCMKit은 모듈식 접근 방식으로 구축되었으므로, 향후 정보 보안 커뮤니티에서 새 모듈과 SCM 시스템을 추가할 수 있습니다.

릴리스

  • SCMKit 버전 1.2는 Releases에서 찾을 수 있습니다.

목차

  • SCMKit
  • 목차
  • 설치/빌드
    • 사용된 라이브러리
    • 사전 컴파일
    • 직접 빌드
  • 사용법
    • 인수/옵션
    • 시스템 (-s, -system)
    • 모듈 (-m, -module)
    • 모듈 상세 표
  • 예시
    • 리포지토리 나열
    • 리포지토리 검색
    • 코드 검색
    • 파일 검색
    • 스니펫 나열
    • 러너 나열
    • Gist 나열
    • 조직 나열
    • API 키 권한 가져오기
    • 관리자 추가
    • 관리자 제거
    • 액세스 토큰 생성
    • 액세스 토큰 나열
    • 액세스 토큰 제거
    • SSH 키 생성
    • SSH 키 나열
    • SSH 키 제거
    • 관리자 통계 나열
    • 브랜치 보호 나열
  • 탐지
  • 참고 자료

설치/빌드

사용된 라이브러리

이 프로젝트는 아래의 타사 라이브러리를 사용합니다.

라이브러리URL라이선스
Octokithttps://github.com/octokit/octokit.netMIT License
Fodyhttps://github.com/Fody/FodyMIT License
GitLabApiClienthttps://github.com/nmklotas/GitLabApiClientMIT License
Newtonsoft.Jsonhttps://github.com/JamesNK/Newtonsoft.JsonMIT License

사전 컴파일

  • Releases에서 사전 컴파일된 바이너리를 사용하세요.

직접 빌드

프로젝트를 직접 컴파일하려면 아래 단계에 따라 Visual Studio를 설정하세요. 이를 위해서는 NuGet 패키지 관리자에서 설치할 수 있는 .NET 라이브러리가 필요합니다.

  • Visual Studio 프로젝트를 로드하고 "Tools" --> "NuGet Package Manager" --> "Package Manager Settings"로 이동합니다.
  • "NuGet Package Manager" --> "Package Sources"로 이동합니다.
  • URL https://api.nuget.org/v3/index.json로 패키지 소스를 추가합니다.
  • 아래 NuGet 패키지를 설치합니다.
    • Install-Package Costura.Fody -Version 3.3.3
    • Install-Package Octokit
    • Install-Package GitLabApiClient
    • Install-Package Newtonsoft.Json
  • 이제 프로젝트를 직접 빌드할 수 있습니다!

사용법

인수/옵션

  • -c, -credential - 인증에 사용할 자격 증명 (username:password 또는 apiKey)
  • -s, -system - 공격할 시스템 (github,gitlab,bitbucket)
  • -u, -url - GitHub Enterprise, GitLab Enterprise 또는 Bitbucket Server의 URL
  • -m, -module - 실행할 모듈
  • -o, -option - 옵션 (해당되는 경우)

시스템 (-s, -system)

  • github: GitHub Enterprise
  • gitlab: GitLab Enterprise
  • bitbucket: Bitbucket Server

모듈 (-m, -module)

  • listrepo: 현재 사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
  • searchrepo: 지정된 리포지토리를 검색합니다.
  • searchcode: 검색 키워드가 포함된 코드를 검색합니다.
  • searchfile: 검색 키워드가 포함된 파일 이름을 검색합니다.
  • listsnippet: 현재 사용자의 모든 스니펫을 나열합니다.
  • listrunner: 현재 사용자가 사용할 수 있는 모든 GitLab 러너를 나열합니다.
  • listgist: 현재 사용자의 모든 gist를 나열합니다.
  • listorg: 현재 사용자가 속한 모든 조직을 나열합니다.
  • privs: 현재 API 토큰의 권한을 가져옵니다.
  • addadmin: 지정된 사용자를 관리자 역할로 승격합니다.
  • removeadmin: 지정된 사용자를 관리자 역할에서 강등합니다.
  • createpat: 대상 사용자의 개인 액세스 토큰을 생성합니다.
  • listpat: 대상 사용자의 개인 액세스 토큰을 나열합니다.
  • removepat: 대상 사용자의 개인 액세스 토큰을 제거합니다.
  • createsshkey: 현재 사용자의 SSH 키를 생성합니다.
  • listsshkey: 현재 사용자의 SSH 키를 나열합니다.
  • removesshkey: 현재 사용자의 SSH 키를 제거합니다.
  • adminstats: 관리자 통계(사용자, 리포지토리, 조직, gist)를 가져옵니다.
  • protection: 브랜치 보호 설정을 가져옵니다.

모듈 상세 표

아래 표는 각 모듈이 지원되는 위치를 보여줍니다.

공격 시나리오모듈관리자 필요?GitHub EnterpriseGitLab EnterpriseBitbucket Server
정찰listrepo아니요XXX
정찰searchrepo아니요XXX
정찰searchcode아니요XXX
정찰searchfile아니요XXX
정찰listsnippet아니요X
정찰listrunner아니요X
정찰listgist아니요X
정찰listorg아니요X
정찰privs아니요XX
정찰protection아니요X
지속listsshkey아니요XXX
지속removesshkey아니요XXX
지속createsshkey아니요XXX
지속listpat아니요XX
지속removepat아니요XX
지속createpat예 (GitLab Enterprise만 해당)XX
권한 상승addadmin예XXX
권한 상승removeadmin예XXX
정찰adminstats예X

예시

리포지토리 나열

사용 사례

특정 SCM 시스템에서 사용 중인 리포지토리를 검색합니다

구문

listrepo 모듈과 함께 관련 인증 정보 및 URL을 제공합니다. 그러면 리포지토리 이름과 URL이 출력됩니다.

GitHub Enterprise

사용자가 볼 수 있는 모든 리포지토리를 나열합니다.

SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local

GitLab Enterprise

사용자가 볼 수 있는 모든 리포지토리를 나열합니다.

SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local

Bitbucket Server

사용자가 볼 수 있는 모든 리포지토리를 나열합니다.

SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local

SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local

예시 출력```

C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local

================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 8:30:47 PM

                                Name | Visibility |                                                URL

                        MaraudersMap |    Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
                        testingStuff |   Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
                           Spellbook |   Internal |    https://gitlab.hogwarts.local/hpotter/spellbook
   findShortestPathToGryffindorSword |   Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
                              charms |     Public |      https://gitlab.hogwarts.local/hgranger/charms
                       Secret-Spells |   Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
                          Monitoring |   Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### 리포지토리 검색

#### 사용 사례

> *특정 SCM 시스템에서 리포지토리 이름으로 리포지토리를 검색합니다*

#### 구문

`-o` 명령줄 스위치에 `searchrepo` 모듈과 검색 조건을 제공하고, 관련 인증 정보와 URL을 함께 지정하세요. 그러면 일치하는 리포지토리 이름과 URL이 출력됩니다.

##### GitHub Enterprise

GitHub 리포지토리 검색은 "포함" 검색입니다. 즉, 입력한 문자열이 이름에 포함된 리포지토리를 검색합니다.

`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`

`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`

##### GitLab Enterprise

GitLab 리포지토리 검색은 "포함" 검색입니다. 즉, 입력한 문자열이 이름에 포함된 리포지토리를 검색합니다.

`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`

`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`

##### Bitbucket Server

Bitbucket 리포지토리 검색은 "시작" 검색입니다. 즉, 입력한 문자열로 시작하는 이름의 리포지토리를 검색합니다.
도구 다운로드