index.md (2960B)
1 --- 2 title: "CI/CD Attacks" 3 section: "DevOps" 4 sectionSlug: "devops" 5 sourcePath: "docs/devops/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/README.md" 7 sha: "203bb0c0b290" 8 isIndex: true 9 --- 10 11 # CI/CD Attacks 12 13 > CI/CD pipelines are often triggered by untrusted actions such a forked pull requests and new issue submissions for public git repositories. These systems often contain sensitive secrets or run in privileged environments. Attackers may gain an RCE into such systems by submitting crafted payloads that trigger the pipelines. Such vulnerabilities are also known as Poisoned Pipeline Execution (PPE). 14 15 ## Summary 16 17 - [Tools](#tools) 18 - [CI/CD Products](#summary) 19 - [GitHub Actions](/internal/devops/cicd-github-actions) 20 - [Gitlab CI](/internal/devops/cicd-gitlab-ci) 21 - [Azure Pipelines (Azure DevOps)](/internal/devops/cicd-azure-devops) 22 - [Circle CI](/internal/devops/cicd-circle-ci) 23 - [Drone CI](/internal/devops/cicd-drone-ci) 24 - [BuildKite](/internal/devops/cicd-buildkite) 25 - [Hardcoded Secrets Enumeration](/internal/devops/secrets-enumeration) 26 - [Package Managers and Build Files](/internal/devops/package-managers) 27 - [References](#references) 28 29 ## Tools 30 31 - [praetorian-inc/gato](https://github.com/praetorian-inc/gato) - GitHub Self-Hosted Runner Enumeration and Attack Tool 32 - [AdnaneKhan/Gato-X](https://github.com/AdnaneKhan/Gato-X) - Fork of Gato - Gato (Github Attack TOolkit) - Extreme Edition 33 - [messypoutine/gravy-overflow](https://github.com/messypoutine/gravy-overflow) - A GitHub Actions Supply Chain CTF / Goat 34 - [xforcered/SCMKit](https://github.com/xforcered/SCMKit) - Source Code Management Attack Toolkit 35 - [synacktiv/octoscan](https://github.com/synacktiv/octoscan) - Octoscan is a static vulnerability scanner for GitHub action workflows. 36 - [synacktiv/gh-hijack-runner](https://github.com/synacktiv/gh-hijack-runner) - A python script to create a fake GitHub runner and hijack pipeline jobs to leak CI/CD secrets. 37 - [synacktiv/nord-stream](https://github.com/synacktiv/nord-stream) - List the secrets stored inside CI/CD environments and extract them by deploying malicious pipelines 38 - [praetorian-inc/glato](https://github.com/praetorian-inc/glato) - GitLab Attack TOolkit 39 40 ## References 41 42 - [Poisoned Pipeline Execution](https://web.archive.org/web/20240226215436/https://www.cidersecurity.io/top-10-cicd-security-risks/poisoned-pipeline-execution-ppe/) 43 - [DEF CON 25 - Exploiting Continuous Integration (CI) and Automated Build systems - spaceB0x - 2 nov. 2017](https://youtu.be/mpUDqo7tIk8) 44 - [Controlling the Source: Abusing Source Code Management Systems - Brett Hawkins - August 9, 2022](https://securityintelligence.com/posts/abusing-source-code-management-systems/) 45 - [Fixing Typos and Breaching Microsoft’s Perimeter - John Stawinski IV - April 15, 2024](https://johnstawinski.com/2024/04/15/fixing-typos-and-breaching-microsofts-perimeter/)