Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
SCMKit — 源代码管理攻击工具包 | Kitploit
工具/GitHubGitHub/xforcered/scmkit
权限提升侦察持久化机制信息收集后渗透利用渗透测试红队
GitHubxforcered/scmkit

SCMKit

源代码管理攻击工具包

查看仓库
13419184年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

SCMKit

描述

源代码管理攻击工具包 - SCMKit 是一个可用于攻击 SCM 系统的工具包。SCMKIT 允许用户指定要使用的 SCM 系统和攻击模块,以及向相应的 SCM 系统提供有效凭据(用户名/密码或 API 密钥)。目前,SCMKIT 支持的 SCM 系统有 GitHub Enterprise、GitLab Enterprise 和 Bitbucket Server。支持的攻击模块包括侦察、权限提升和持久化。SCMKIT 采用模块化方式构建,以便信息安全社区将来可以添加新模块和 SCM 系统。

发布

  • 可在 Releases 中找到 SCMKit 的 1.2 版本

目录

  • SCMKit
  • 目录
  • 安装/构建
    • 使用的库
    • 预编译
    • 自行构建
  • 用法
    • 参数/选项
    • 系统
    • 模块
    • 模块详情表
  • 示例
    • 列出仓库
    • 搜索仓库
    • 搜索代码
    • 搜索文件
    • 列出片段
    • 列出 Runner
    • 列出 Gist
    • 列出组织
    • 获取 API 密钥权限
    • 添加管理员
    • 移除管理员
    • 创建访问令牌
    • 列出访问令牌
    • 移除访问令牌
    • 创建 SSH 密钥
    • 列出 SSH 密钥
    • 移除 SSH 密钥
    • 列出管理员统计信息
    • 列出分支保护
  • 检测
  • 参考

安装/构建

使用的库

本项目使用了以下第三方库。

库URL许可证
Octokithttps://github.com/octokit/octokit.netMIT License
Fodyhttps://github.com/Fody/FodyMIT License
GitLabApiClienthttps://github.com/nmklotas/GitLabApiClientMIT License
Newtonsoft.Jsonhttps://github.com/JamesNK/Newtonsoft.JsonMIT License

预编译

  • 使用 Releases 中的预编译二进制文件

自行构建

按照以下步骤设置 Visual Studio,以便自行编译项目。这需要 .NET 库,该库可通过 NuGet 包管理器安装。

  • 打开 Visual Studio 项目,转到“工具”-->“NuGet 包管理器”-->“包管理器设置”
  • 转到“NuGet 包管理器”-->“包源”
  • 添加一个包源,URL 为 https://api.nuget.org/v3/index.json
  • 安装以下 NuGet 包
    • Install-Package Costura.Fody -Version 3.3.3
    • Install-Package Octokit
    • Install-Package GitLabApiClient
    • Install-Package Newtonsoft.Json
  • 现在你可以自行构建项目了!

用法

参数/选项

  • -c, -credential - 用于身份验证的凭据(username:password 或 apiKey)
  • -s, -system - 要攻击的系统(github、gitlab、bitbucket)
  • -u, -url - GitHub Enterprise、GitLab Enterprise 或 Bitbucket Server 的 URL
  • -m, -module - 要运行的模块
  • -o, -option - 选项(适用时)

系统(-s、-system)

  • github: GitHub Enterprise
  • gitlab: GitLab Enterprise
  • bitbucket: Bitbucket Server

模块(-m、-module)

  • listrepo: 列出当前用户可见的所有仓库
  • searchrepo: 搜索指定的仓库
  • searchcode: 搜索包含关键字搜索词的代码
  • searchfile: 搜索包含关键字搜索词的文件名
  • listsnippet: 列出当前用户的所有片段(snippet)
  • listrunner: 列出当前用户可用的所有 GitLab runner
  • listgist: 列出当前用户的所有 gist
  • listorg: 列出当前用户所属的所有组织(org)
  • privs: 获取当前 API 令牌的权限
  • addadmin: 将指定用户提升为管理员角色
  • removeadmin: 将指定用户从管理员角色降级
  • createpat: 为目标用户创建个人访问令牌
  • listpat: 列出目标用户的个人访问令牌
  • removepat: 删除目标用户的个人访问令牌
  • createsshkey: 为当前用户创建 SSH 密钥
  • listsshkey: 列出当前用户的 SSH 密钥
  • removesshkey: 删除当前用户的 SSH 密钥
  • adminstats: 获取管理员统计信息(用户、仓库、组织、gist)
  • protection: 获取分支保护设置

模块详情表

下表显示了每个模块在哪些系统中受支持

攻击场景模块是否需要管理员?GitHub EnterpriseGitLab EnterpriseBitbucket Server
侦察listrepo否XXX
侦察searchrepo否XXX
侦察searchcode否XXX
侦察searchfile否XXX
侦察listsnippet否X
侦察listrunner否X
侦察listgist否X
侦察listorg否X
侦察privs否XX
侦察protection否X
持久化listsshkey否XXX
持久化removesshkey否XXX
持久化createsshkey否XXX
持久化listpat否XX
持久化removepat否XX
持久化createpat是(仅 GitLab Enterprise)XX
权限提升addadmin是XXX
权限提升removeadmin是XXX
侦察adminstats是X

示例

列出仓库

使用场景

发现特定 SCM 系统中正在使用的仓库

语法

提供 listrepo 模块,以及任何相关的身份验证信息和 URL。这将输出仓库名称和 URL。

GitHub Enterprise

这将列出用户可以看到的所有仓库。

SCMKit.exe -s github -m listrepo -c userName:password -u https://github.something.local

SCMKit.exe -s github -m listrepo -c apiKey -u https://github.something.local

GitLab Enterprise

这将列出用户可以看到的所有仓库。

SCMKit.exe -s gitlab -m listrepo -c userName:password -u https://gitlab.something.local

SCMKit.exe -s gitlab -m listrepo -c apiKey -u https://gitlab.something.local

Bitbucket Server

这将列出用户可以看到的所有仓库。

SCMKit.exe -s bitbucket -m listrepo -c userName:password -u https://bitbucket.something.local

SCMKit.exe -s bitbucket -m listrepo -c apiKey -u https://bitbucket.something.local

示例输出```

C:>SCMKit.exe -s gitlab -m listrepo -c username:password -u https://gitlab.hogwarts.local

================================================== Module: listrepo System: gitlab Auth Type: Username/Password Options: Target URL: https://gitlab.hogwarts.local

Timestamp: 1/14/2022 8:30:47 PM

                                Name | Visibility |                                                URL

                        MaraudersMap |    Private | https://gitlab.hogwarts.local/hpotter/maraudersmap
                        testingStuff |   Internal | https://gitlab.hogwarts.local/adumbledore/testingstuff
                           Spellbook |   Internal |    https://gitlab.hogwarts.local/hpotter/spellbook
   findShortestPathToGryffindorSword |   Internal | https://gitlab.hogwarts.local/hpotter/findShortestPathToGryffindorSword
                              charms |     Public |      https://gitlab.hogwarts.local/hgranger/charms
                       Secret-Spells |   Internal | https://gitlab.hogwarts.local/adumbledore/secret-spells
                          Monitoring |   Internal | https://gitlab.hogwarts.local/gitlab-instance-10590c85/Monitoring
### 搜索仓库

#### 使用场景

> *在特定的 SCM 系统中按仓库名称搜索仓库*

#### 语法

在 `-o` 命令行开关中提供 `searchrepo` 模块和你的搜索条件,并附上任何相关的认证信息和 URL。这将输出匹配的仓库名称和 URL。

##### GitHub Enterprise

GitHub 仓库搜索是一种“包含”搜索,你输入的字符串会用于搜索名称包含该搜索词的仓库。

`SCMKit.exe -s github -m searchrepo -c userName:password -u https://github.something.local -o "some search term"`

`SCMKit.exe -s github -m searchrepo -c apikey -u https://github.something.local -o "some search term"`

##### GitLab Enterprise

GitLab 仓库搜索是一种“包含”搜索,你输入的字符串会用于搜索名称包含该搜索词的仓库。

`SCMKit.exe -s gitlab -m searchrepo -c userName:password -u https://gitlab.something.local -o "some search term"`

`SCMKit.exe -s gitlab -m searchrepo -c apikey -u https://gitlab.something.local -o "some search term"`

##### Bitbucket Server

Bitbucket 仓库搜索是一种“以……开头”搜索,你输入的字符串会用于搜索名称以该搜索词开头的仓库。

`SCMKit.exe -s bitbucket -m searchrepo -c userName:password -u https://bitbucket.something.local -o "some search term"`

`SCMKit.exe -s bitbucket -m searchrepo -c apikey -u https://bitbucket.something.local -o "some search term"`

#### 示例输出```

C:\>SCMKit.exe -s gitlab -m searchrepo -c apiKey -u https://gitlab.hogwarts.local -o "spell"

==================================================
Module:         searchrepo
System:         gitlab
Auth Type:      API Key
Options:        spell
Target URL:     https://gitlab.hogwarts.local

Timestamp:      1/14/2022 8:32:30 PM
==================================================
下载工具