
소스 코드 관리 공격 툴킷
Source Code Management Attack Toolkit - SCMKit은 SCM 시스템을 공격하는 데 사용할 수 있는 툴킷입니다. SCMKit을 사용하면 SCM 시스템과 사용할 공격 모듈을 지정하고, 해당 SCM 시스템에 대한 유효한 자격 증명(사용자 이름/비밀번호 또는 API 키)을 지정할 수 있습니다. 현재 SCMKit이 지원하는 SCM 시스템은 GitHub Enterprise, GitLab Enterprise 및 Bitbucket Server입니다. 지원되는 공격 모듈에는 정찰, 권한 상승 및 지속이 포함됩니다. SCMKit은 모듈식 접근 방식으로 구축되었으므로, 향후 정보 보안 커뮤니티에서 새 모듈과 SCM 시스템을 추가할 수 있습니다.
이 프로젝트는 아래의 타사 라이브러리를 사용합니다.
| 라이브러리 | URL | 라이선스 |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
프로젝트를 직접 컴파일하려면 아래 단계에 따라 Visual Studio를 설정하세요. 이를 위해서는 NuGet 패키지 관리자에서 설치할 수 있는 .NET 라이브러리가 필요합니다.
https://api.nuget.org/v3/index.json로 패키지 소스를 추가합니다.Install-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Json아래 표는 각 모듈이 지원되는 위치를 보여줍니다.
| 공격 시나리오 | 모듈 | 관리자 필요? | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| 정찰 | listrepo | 아니요 | X | X | X |
| 정찰 | searchrepo | 아니요 | X | X | X |
| 정찰 | searchcode | 아니요 | X | X | X |
| 정찰 | searchfile | 아니요 | X | X | X |
| 정찰 | listsnippet | 아니요 | X | ||
| 정찰 | listrunner | 아니요 | X | ||
| 정찰 | listgist | 아니요 | X | ||
| 정찰 | listorg | 아니요 | X | ||
| 정찰 | privs | 아니요 | X | X | |
| 정찰 | protection | 아니요 | X | ||
| 지속 | listsshkey | 아니요 | X | X | X |
| 지속 | removesshkey | 아니요 | X | X | X |
| 지속 | createsshkey | 아니요 | X | X | X |
| 지속 | listpat | 아니요 | X | X | |
| 지속 | removepat | 아니요 | X | X | |
| 지속 | createpat | 예 (GitLab Enterprise만 해당) | X | X | |
| 권한 상승 | addadmin | 예 | X | X | X |
| 권한 상승 | removeadmin | 예 | X | X | X |
| 정찰 | adminstats | 예 | X |
특정 SCM 시스템에서 사용 중인 리포지토리를 검색합니다
listrepo 모듈과 함께 관련 인증 정보 및 URL을 제공합니다. 그러면 리포지토리 이름과 URL이 출력됩니다.
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
사용자가 볼 수 있는 모든 리포지토리를 나열합니다.
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local
Name | Visibility | URL
MaraudersMap | Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
testingStuff | Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
Spellbook | Internal | https://gitlab.hogwarts.local/hpotter/spellbook
findShortestPathToGryffindorSword | Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
charms | Public | https://gitlab.hogwarts.local/hgranger/charms
Secret-Spells | Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
Monitoring | Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### 리포지토리 검색
#### 사용 사례
> *특정 SCM 시스템에서 리포지토리 이름으로 리포지토리를 검색합니다*
#### 구문
`-o` 명령줄 스위치에 `searchrepo` 모듈과 검색 조건을 제공하고, 관련 인증 정보와 URL을 함께 지정하세요. 그러면 일치하는 리포지토리 이름과 URL이 출력됩니다.
##### GitHub Enterprise
GitHub 리포지토리 검색은 "포함" 검색입니다. 즉, 입력한 문자열이 이름에 포함된 리포지토리를 검색합니다.
`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`
`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`
##### GitLab Enterprise
GitLab 리포지토리 검색은 "포함" 검색입니다. 즉, 입력한 문자열이 이름에 포함된 리포지토리를 검색합니다.
`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`
`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`
##### Bitbucket Server
Bitbucket 리포지토리 검색은 "시작" 검색입니다. 즉, 입력한 문자열로 시작하는 이름의 리포지토리를 검색합니다.