源代码管理攻击工具包 - SCMKit 是一个可用于攻击 SCM 系统的工具包。SCMKIT 允许用户指定要使用的 SCM 系统和攻击模块,以及向相应的 SCM 系统提供有效凭据(用户名/密码或 API 密钥)。目前,SCMKIT 支持的 SCM 系统有 GitHub Enterprise、GitLab Enterprise 和 Bitbucket Server。支持的攻击模块包括侦察、权限提升和持久化。SCMKIT 采用模块化方式构建,以便信息安全社区将来可以添加新模块和 SCM 系统。
本项目使用了以下第三方库。
| 库 | URL | 许可证 |
|---|---|---|
| Octokit | https://github.com/octokit/octokit.net | MIT License |
| Fody | https://github.com/Fody/Fody | MIT License |
| GitLabApiClient | https://github.com/nmklotas/GitLabApiClient | MIT License |
| Newtonsoft.Json | https://github.com/JamesNK/Newtonsoft.Json | MIT License |
按照以下步骤设置 Visual Studio,以便自行编译项目。这需要 .NET 库,该库可通过 NuGet 包管理器安装。
https://api.nuget.org/v3/index.jsonInstall-Package Costura.Fody -Version 3.3.3Install-Package OctokitInstall-Package GitLabApiClientInstall-Package Newtonsoft.Json下表显示了每个模块在哪些系统中受支持
| 攻击场景 | 模块 | 是否需要管理员? | GitHub Enterprise | GitLab Enterprise | Bitbucket Server |
|---|---|---|---|---|---|
| 侦察 | listrepo | 否 | X | X | X |
| 侦察 | searchrepo | 否 | X | X | X |
| 侦察 | searchcode | 否 | X | X | X |
| 侦察 | searchfile | 否 | X | X | X |
| 侦察 | listsnippet | 否 | X | ||
| 侦察 | listrunner | 否 | X | ||
| 侦察 | listgist | 否 | X | ||
| 侦察 | listorg | 否 | X | ||
| 侦察 | privs | 否 | X | X | |
| 侦察 | protection | 否 | X | ||
| 持久化 | listsshkey | 否 | X | X | X |
| 持久化 | removesshkey | 否 | X | X | X |
| 持久化 | createsshkey | 否 | X | X | X |
| 持久化 | listpat | 否 | X | X | |
| 持久化 | removepat | 否 | X | X | |
| 持久化 | createpat | 是(仅 GitLab Enterprise) | X | X | |
| 权限提升 | addadmin | 是 | X | X | X |
| 权限提升 | removeadmin | 是 | X | X | X |
| 侦察 | adminstats | 是 | X |
发现特定 SCM 系统中正在使用的仓库
提供 listrepo 模块,以及任何相关的身份验证信息和 URL。这将输出仓库名称和 URL。
这将列出用户可以看到的所有仓库。
SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local
SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local
这将列出用户可以看到的所有仓库。
SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local
SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local
这将列出用户可以看到的所有仓库。
SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local
SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local
C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local
================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local
Name | Visibility | URL
MaraudersMap | Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
testingStuff | Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
Spellbook | Internal | https://gitlab.hogwarts.local/hpotter/spellbook
findShortestPathToGryffindorSword | Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
charms | Public | https://gitlab.hogwarts.local/hgranger/charms
Secret-Spells | Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
Monitoring | Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### 搜索仓库
#### 使用场景
> *在特定的 SCM 系统中按仓库名称搜索仓库*
#### 语法
在 `-o` 命令行开关中提供 `searchrepo` 模块和你的搜索条件,并附上任何相关的认证信息和 URL。这将输出匹配的仓库名称和 URL。
##### GitHub Enterprise
GitHub 仓库搜索是一种“包含”搜索,你输入的字符串会用于搜索名称包含该搜索词的仓库。
`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`
`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`
##### GitLab Enterprise
GitLab 仓库搜索是一种“包含”搜索,你输入的字符串会用于搜索名称包含该搜索词的仓库。
`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`
`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`
##### Bitbucket Server
Bitbucket 仓库搜索是一种“以……开头”搜索,你输入的字符串会用于搜索名称以该搜索词开头的仓库。
`SCMKit.exe -s bitbucket -m searchrepo -c userName:password -u https://bitbucket.something.local -o "some search term"`
`SCMKit.exe -s bitbucket -m searchrepo -c apikey -u https://bitbucket.something.local -o "some search term"`
#### 示例输出```
C:\>SCMKit.exe -s gitlab -m searchrepo -c apiKey -u https://gitlab.hogwarts.local -o "spell"
==================================================
Module: searchrepo
System: gitlab
Auth Type: API Key
Options: spell
Target URL: https://gitlab.hogwarts.local
Timestamp: 1/14/2022 8:32:30 PM
==================================================