index.md (2620B)
1 --- 2 title: "Dependency Confusion" 3 topic: "Dependency Confusion" 4 topicSlug: "dependency-confusion" 5 sourcePath: "Dependency Confusion/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Dependency%20Confusion/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Dependency Confusion 12 13 > A dependency confusion attack or supply chain substitution attack occurs when a software installer script is tricked into pulling a malicious code file from a public repository instead of the intended file of the same name from an internal repository. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [NPM Example](#npm-example) 20 * [References](#references) 21 22 ## Tools 23 24 * [visma-prodsec/confused](https://github.com/visma-prodsec/confused) - Tool to check for dependency confusion vulnerabilities in multiple package management systems 25 * [synacktiv/DepFuzzer](https://github.com/synacktiv/DepFuzzer) - Tool used to find dependency confusion or project where owner's email can be takeover. 26 27 ## Methodology 28 29 Look for `npm`, `pip`, `gem` packages, the methodology is the same : you register a public package with the same name of private one used by the company and then you wait for it to be used. 30 31 * **DockerHub**: Dockerfile image 32 * **JavaScript** (npm): package.json 33 * **MVN** (maven): pom.xml 34 * **PHP** (composer): composer.json 35 * **Python** (pypi): requirements.txt 36 37 ### NPM Example 38 39 * List all the packages (ie: package.json, composer.json, ...) 40 * Find the package missing from [www.npmjs.com](https://www.npmjs.com/) 41 * Register and create a **public** package with the same name 42 * Package example : [0xsapra/dependency-confusion-expoit](https://github.com/0xsapra/dependency-confusion-expoit) 43 44 ## References 45 46 * [Exploiting Dependency Confusion - Aman Sapra (0xsapra) - July 2, 2021](https://web.archive.org/web/20251107024922/https://0xsapra.github.io/website/Exploiting-Dependency-Confusion) 47 * [Dependency Confusion: How I Hacked Into Apple, Microsoft and Dozens of Other Companies - Alex Birsan - February 9, 2021](https://web.archive.org/web/20210209181139/https://medium.com/@alex.birsan/dependency-confusion-4a5d60fec610) 48 * [3 Ways to Mitigate Risk When Using Private Package Feeds - Microsoft - March 29, 2021](https://web.archive.org/web/20210210121930/https://azure.microsoft.com/en-gb/resources/3-ways-to-mitigate-risk-using-private-package-feeds/) 49 * [$130,000+ Learn New Hacking Technique in 2021 - Dependency Confusion - Bug Bounty Reports Explained - February 22, 2021](https://web.archive.org/web/20210223060107/https://www.youtube.com/watch?v=zFHJwehpBrU)